Junglewise Threat Intelligence

CVE-2026-78082: JoomShaper SP Property unauthenticated SQL injection in search filtering

CVE-2026-78082 · Severity: info · CVSS 7.5 · Published 2026-09-10

Technologies: JoomShaper SP Property. Vendors: JoomShaper.

Executive brief

SP Property is a Joomla real estate management extension used by property agencies and portals to list and manage property listings. An unauthenticated attacker can exploit SQL injection vulnerabilities in the property search and filtering functionality to extract sensitive data from the website's database, compromising customer information, property details, and other confidential business data without requiring login credentials.

Technical details

The vulnerability is an unauthenticated SQL injection flaw in the property search and map filtering query builders. The vulnerable component directly concatenates user-supplied request parameters (zipcode, sorting, price_range_dropdown, and psize_range_dropdown) into SQL WHERE and ORDER BY clauses without quoting or type casting. An attacker can craft malicious input to execute boolean-based or time-based blind SQL injection attacks to extract arbitrary data from the database. The vulnerability affects SP Property versions below 4.1.4 and is exploitable remotely without authentication or user interaction.

Affected products

  • JoomShaper SP Property < 4.1.4

Timeline

  • 2026-09-10: disclosed

References

Related threats