Joomla! SP Page Builder是Joomla!组织的一款Joomla!页面构建器扩展组件。 Joomla SP Page Builder 1.0.0版本至6.7.1版本存在路径遍历漏洞,该漏洞源于未正确验证文件路径,可能导致未经身份验证的攻击者包含系统可访问的任意本地PHP文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| joomshaper.com | SP Page Builder extension for Joomla | 1.0.0-6.7.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| joomshaper.com | SP Page Builder extension for Joomla | 1.0.0-6.7.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67286 | 6.3 MEDIUM | Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file |
| CVE-2026-67287 | 6.3 MEDIUM | Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < |
No comments yet