Junglewise Threat Intelligence

CVE-2026-81565: JoomShaper SP Page Builder arbitrary file upload directory traversal

CVE-2026-81565 · Severity: info · CVSS 7.5 · Published 2026-09-14

Technologies: JoomShaper SP Page Builder, JoomShaper SP Page Builder Pro. Vendors: JoomShaper.

Executive brief

SP Page Builder is a drag-and-drop page composer extension for Joomla used by hundreds of thousands of websites. An attacker could bypass directory restrictions during file uploads and place files into sensitive directories like administrator folders or the site root, potentially enabling remote code execution or unauthorized access to administrative functions.

Technical details

A missing directory confinement vulnerability exists in the media upload functionality of SP Page Builder (Free and Pro versions 4.0.0–6.9.0). The vulnerability stems from insufficient input validation on the "folder" request parameter, which replaces the generated date-based destination folder path and is passed to Folder::create() and File::upload() functions without boundary checks. This allows attackers to write files into any directory beneath the web root, including administrator/, templates/, cli/, and the site root. While Joomla's PATH input filter prevents traversal above the web root and existing files are not overwritten, the ability to write into sensitive directories presents a significant security risk. No authentication requirement is explicitly stated, suggesting the upload endpoint may be accessible to unauthenticated users or low-privileged users.

Affected products

  • JoomShaper SP Page Builder 4.0.0–6.9.0
  • JoomShaper SP Page Builder Pro 4.0.0–6.9.0

Timeline

  • 2026-09-14: disclosed: CVE-2026-81565 published on NVD

References

Related threats