Joomla 扩展 – joomshaper.com – SP Page Builder Pro 3.2.6 至 6.9.0 版本中,Contact、Opt-in 和 Form Builder 插件在模块上下文中存在未认证的验证码绕过漏洞 在 ajax_contact、optin_form 和 form_builder 插件中,当请求提供的 view_type 参数等于 "module" 时,验证码插件的 onCheckAnswer 事件返回的结果会被丢弃,并替换为对非空字符串的测试。因此,提交 view_type
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| joomshaper.com | SP Page Builder (Pro) extension for Joomla | 3.2.6 - 6.9.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78375 | 8.6 HIGH | Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content |
| CVE-2026-81564 | 7.0 HIGH | Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing |
| CVE-2026-81565 | 6.9 MEDIUM | Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Pa |
| CVE-2026-79700 | 6.9 MEDIUM | Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled |
| CVE-2026-81566 | 5.1 MEDIUM | Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Pag |
No comments yet