Junglewise Threat Intelligence

CVE-2026-65877: JoomShaper SP Page Builder SQL injection in media manager

CVE-2026-65877 · Severity: info · CVSS 7.1 · Published 2026-07-27

Technologies: JoomShaper SP Page Builder. Vendors: JoomShaper.

Executive brief

JoomShaper SP Page Builder is a popular drag-and-drop design tool for the Joomla content management system. A security flaw in the media manager component allows users with low-level editing permissions to perform unauthorized database queries. This could lead to the exposure of sensitive information stored in the website's database, such as user details or site configuration.

Technical details

An authenticated SQL injection vulnerability exists in SP Page Builder versions prior to 6.7.1. The media manager's JSON view (specifically in media.php within the getDateFilters and getTotalMedia functions) fails to properly escape or validate search and date parameters before incorporating them into SQL queries. An attacker with low-privilege 'Author' permissions can exploit this to read arbitrary data from the Joomla database. The vulnerability is further exacerbated by a lack of CSRF tokens on the affected view. The issue was resolved in version 6.7.1 by implementing proper input validation and escaping.

Affected products

  • JoomShaper SP Page Builder extension for Joomla 1.0.0 - 6.7.0

Timeline

  • 2026-07-27: patched: Fixed in version 6.7.1
  • 2026-07-27: advisory

References

Related threats