VulnSea

joomshaper.com has 12 CVEs on record. Disclosure cadence is accelerating: 12 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 12. The median CVSS is 6.9 (medium), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-22 (3). Most affected products: SP Property extension for Joomla (6), SP Page Builder (Free and Pro) extension for Joomla (4), SP Page Builder (Pro) extension for Joomla (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.9
Publish → KEV
Last 90 days
12 prev 0

Products

  • SP Property extension for Joomla 6
  • SP Page Builder (Free and Pro) extension for Joomla 4
  • SP Page Builder (Pro) extension for Joomla 2
12
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

joomshaper.com vulnerabilities

CVEs affecting joomshaper.com, newest first. Open any entry for full detail, references, and exploit status.

12 CVEsRSS

CVE-2026-81566Medium· 5.1
1w ago

Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The add-to-menu routine invoked the com_menus item model's save() method directly

Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The add-to-menu routine invoked the com_menus item model's save() method directly. That model does not per…

Sunlitjoomshaper.com · SP Page Builder (Free and Pro) extension for JoomlaEPSS 0.23%via NVD
CVE-2026-81565Medium· 6.9
1w ago

Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The folder request parameter replaced the generated date-based destination folder in its entirety and was…

Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The folder request parameter replaced the generated date-based destination folder in its entirety and was…

Sunlitjoomshaper.com · SP Page Builder (Free and Pro) extension for JoomlaEPSS 0.31%via NVD
CVE-2026-81564High· 7.0
1w ago

Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The media rename task applied neither of the directory boundary checks use…

Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The media rename task applied neither of the directory boundary checks use…

Twilightjoomshaper.com · SP Page Builder (Free and Pro) extension for JoomlaEPSS 0.31%via NVD
CVE-2026-79701Medium· 6.9
1w ago

Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 6.9.0 - In the ajax_contact, optin_form and form_builder addons, the resul…

Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 6.9.0 - In the ajax_contact, optin_form and form_builder addons, the resul…

Sunlitjoomshaper.com · SP Page Builder (Pro) extension for JoomlaEPSS 0.27%via NVD
CVE-2026-79700Medium· 6.9
1w ago

Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 - The optin_form addon read the CAPTCHA type, the expected answer and the enabled flag f…

Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 - The optin_form addon read the CAPTCHA type, the expected answer and the enabled flag f…

Sunlitjoomshaper.com · SP Page Builder (Pro) extension for JoomlaEPSS 0.27%via NVD
CVE-2026-78375High· 8.6
1w ago

Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0 - plgContentSppagebuilder::onContentAfterSave() read jform[attribs][sppagebuilder_article_id…

Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0 - plgContentSppagebuilder::onContentAfterSave() read jform[attribs][sppagebuilder_article_id…

Twilightjoomshaper.com · SP Page Builder (Free and Pro) extension for JoomlaEPSS 0.22%via NVD
CVE-2026-78303Medium· 6.9
1w ago

Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing pote…

Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing pote…

Sunlitjoomshaper.com · SP Property extension for JoomlaEPSS 0.25%via NVD
CVE-2026-78302High· 8.6
1w ago

Joomla Extension - joomshaper.com - Unauthenticated Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and administrator list tables rend…

Twilightjoomshaper.com · SP Property extension for JoomlaEPSS 0.26%via CVEORG
CVE-2026-78085Medium· 6.9
1w ago

Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks.

Sunlitjoomshaper.com · SP Property extension for JoomlaEPSS 0.36%via CVEORG
CVE-2026-78084Medium· 6.9
1w ago

Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked authorization checks and CSRF token validation.. Users could invoke file remo…

Sunlitjoomshaper.com · SP Property extension for JoomlaEPSS 0.18%via CVEORG
CVE-2026-78083High· 7.1
1w ago

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 - The visitor booking (properties.booking) and agent contact form submission (agents.sendmail) end…

Twilightjoomshaper.com · SP Property extension for JoomlaEPSS 0.21%via CVEORG
CVE-2026-78082Critical· 9.3
1w ago

Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting…

Midnightjoomshaper.com · SP Property extension for JoomlaEPSS 0.49%via CVEORG
joomshaper.com vulnerabilities (CVEs) · VulnSea