VulnSea

sp_property_extension_for_joomla vulnerabilities

CVEs whose affected-version data names the sp_property_extension_for_joomla package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-78303Medium· 6.9
2w ago

Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing pote…

Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing pote…

▾ Sunlitjoomshaper.com · SP Property extension for JoomlaEPSS 0.43%via NVD
CVE-2026-78302High· 8.6
2w ago

Joomla Extension - joomshaper.com - Unauthenticated Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and administrator list tables rend…

▾ Twilightjoomshaper.com · SP Property extension for JoomlaEPSS 0.44%via CVEORG
CVE-2026-78085Medium· 6.9
2w ago

Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks.

▾ Sunlitjoomshaper.com · SP Property extension for JoomlaEPSS 0.50%via CVEORG
CVE-2026-78084Medium· 6.9
2w ago

Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked authorization checks and CSRF token validation.. Users could invoke file remo…

▾ Sunlitjoomshaper.com · SP Property extension for JoomlaEPSS 0.33%via CVEORG
CVE-2026-78083High· 7.1
2w ago

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 - The visitor booking (properties.booking) and agent contact form submission (agents.sendmail) end…

▾ Twilightjoomshaper.com · SP Property extension for JoomlaEPSS 0.21%via CVEORG
CVE-2026-78082Critical· 9.3
2w ago

Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting…

▾ Midnightjoomshaper.com · SP Property extension for JoomlaEPSS 0.51%via CVEORG
sp_property_extension_for_joomla vulnerabilities (CVEs) · VulnSea