Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81564— Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0

Quick assessment

Affected
joomshaper.com SP Page Builder (Free and Pro) extension for Joomla
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

这段文字描述了一个存在于 Joomla 扩展 joomshaper.com 的 SP Page Builder(免费版和 Pro 版,版本范围 4.0.0 - 6.9.0) 中的漏洞。 以下是该漏洞描述的中文翻译: Joomla 扩展 - joomshaper.com - SP Page Builder(免费版和 Pro 版,4.0.0 - 6.9.0)中“媒体重命名”功能存在目录约束缺失问题,允许任意文件重命名 在该控制器中,媒体重命名任务并未应用与其他文件夹操作相同的目录边界检查,且其验证机制仅要求“提供的标识

CVSS 7.0 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81564

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0
Source: CVE Program / CVE List V5
Vulnerability Description
Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The media rename task applied neither of the directory boundary checks used by the folder operations in the same controller, and its validation guard required only that either a media record exist for the supplied identifier or that the supplied path be present in #__spmedia, rather than both. The identifier and the path were consequently never checked against one another, so any valid media identifier could be paired with an unrelated filesystem path, and the STR input filter left traversal sequences intact. An attacker could rename files elsewhere in the installation, including renaming configuration.php to take the site offline.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:L/SA:L
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
joomshaper.com SP Page Builder (Free and Pro) extension for Joomla 4.0.0 - 6.9.0 -

II. Public POCs for CVE-2026-81564

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81564

登录查看更多情报信息。

Vendor Pages for CVE-2026-81564 (1)

Same Patch Batch · joomshaper.com · 2026-09-14 · 6 CVEs total

CVE-2026-78375 8.6 HIGH Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content
CVE-2026-81565 6.9 MEDIUM Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Pa
CVE-2026-79700 6.9 MEDIUM Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled
CVE-2026-79701 6.9 MEDIUM Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in th
CVE-2026-81566 5.1 MEDIUM Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Pag

IV. Related Vulnerabilities

V. Comments for CVE-2026-81564

No comments yet


Leave a comment