Каталог CVE

Расширение: SP Page Builder

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 10

Расширение: SP Page Builder
Средняя CVSS 6.3

CVE-2026-67287

Разработчикjoomshaper.com

Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in questi…

12.08.2026 Активна
Средняя CVSS 6.3

CVE-2026-67286

Разработчикjoomshaper.com

Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name.

12.08.2026 Активна
Критическая CVSS 9.2

CVE-2026-67285

Разработчикjoomshaper.com

Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbitrary PHP files that are accessible by the system.

12.08.2026 Требует внимания
Высокая CVSS 8.7

CVE-2026-66494

Разработчикjoomshaper.com

Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request.…

07.08.2026 Требует внимания
Критическая CVSS 9.8

CVE-2026-65879

Разработчикjoomshaper.com

Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.

27.07.2026 Требует внимания
Высокая CVSS 8.3

CVE-2026-65878

Разработчикjoomshaper.com

Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.

27.07.2026 Требует внимания
Высокая CVSS 8.2

CVE-2026-65877

Разработчикjoomshaper.com

Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector.

27.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-65876

Разработчикjoomshaper.com

Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector.

27.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-65766

Разработчикjoomshaper.com

Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector.

27.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-48908

РасширениеSP Page Builder
РазработчикJoomShaper

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

20.06.2026 Требует внимания