Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0 - plg...
joomshaper.com CVEs
15 high and critical vulnerabilities covered by CVE Brief since 2026-06-30, each with independent analyst commentary.
← All vendors RSS feed Watch this vendorProfile
Last 12 months
15 CVEs in the last 12 months
Products
- SP Page Builder extension for Joomla5
- Helix Ultimate extension for Joomla4
- SP Property extension for Joomla2
- Easy Store extension for Joomla2
- SP Page Builder1
- Helix3 extension for Joomla1
6 products in total
Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.
Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4...
An unauthenticated SQL injection vulnerability in the SP Property extension for Joomla allows remote attackers to extract sensitive database informati...
Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously validated...
Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10 - Unsani...
Joomla Extension - joomshaper
Joomla Extension - joomshaper
Joomla Extension - joomshaper
The SP Page Builder extension for Joomla contains an unauthenticated SQL injection vulnerability in the loadMoreArticles endpoint due to improper vali...
The SP Page Builder extension for Joomla contains an unauthenticated SQL injection vulnerability in the Dynamic Content endpoint due to improper valid...
The Easy Store extension for Joomla is vulnerable to an unauthenticated SQL injection, allowing remote attackers to access database credentials and se...
Joomla Extension - joomshaper
The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion
The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files...