Junglewise Threat Intelligence

CVE-2026-65876: JoomShaper SP Page Builder SQL injection in loadMoreArticles

CVE-2026-65876 · Severity: info · CVSS 9.2 · Published 2026-07-27

Technologies: JoomShaper SP Page Builder. Vendors: JoomShaper.

Executive brief

A security vulnerability exists in SP Page Builder, a popular tool used to design and build Joomla websites. An unauthorized attacker can exploit this flaw to gain access to the website's underlying database without needing a username or password. This could lead to the theft of sensitive customer data, administrative credentials, or other private site information.

Technical details

An unauthenticated SQL injection vulnerability exists in JoomShaper SP Page Builder versions prior to 6.7.1. The flaw is located within the 'loadMoreArticles' endpoint, where the 'catid' parameter is processed without sufficient validation or sanitization. A remote, unauthenticated attacker can send specially crafted web requests to execute arbitrary SQL commands against the backend database. This can be leveraged to extract sensitive information, bypass authentication, or potentially gain further access to the Joomla environment. The issue is addressed in version 6.7.1.

Affected products

  • JoomShaper SP Page Builder extension for Joomla 1.0.0 to 6.7.0

Timeline

  • 2026-07-27: advisory
  • 2026-07-27: disclosed

References

Related threats