15 Total CVEs
15 AI Analyzed
0 CISA KEV
4 Critical

Profile

0% ended up actively exploited 0 of 15 added to CISA KEV
27% rated critical (CVSS 9.0+) 4 critical, 11 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

15 CVEs in the last 12 months

Products

  • SP Page Builder extension for Joomla5
  • Helix Ultimate extension for Joomla4
  • SP Property extension for Joomla2
  • Easy Store extension for Joomla2
  • SP Page Builder1
  • Helix3 extension for Joomla1

6 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-15 of 15 CVEs
CVE-2026-78375
Analyzed
8.6
joomshaper.com SP Page Builder

Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0 - plg...

2026-09-15
Full analysis →
CVE-2026-78302
Analyzed
8.6
joomshaper.com SP Property extension for Joomla

Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4...

2026-09-11
Full analysis →
CVE-2026-78082
Analyzed
9.3
joomshaper.com SP Property extension for Joomla

An unauthenticated SQL injection vulnerability in the SP Property extension for Joomla allows remote attackers to extract sensitive database informati...

2026-09-11
Full analysis →
CVE-2026-78078
Analyzed
8.9
joomshaper.com Helix Ultimate extension for Joomla

Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously validated...

2026-09-01
Full analysis →
CVE-2026-78077
Analyzed
8.6
joomshaper.com Helix Ultimate extension for Joomla

Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10 - Unsani...

2026-09-01
Full analysis →
CVE-2026-65876
Analyzed
9.2
joomshaper.com SP Page Builder extension for Joomla

The SP Page Builder extension for Joomla contains an unauthenticated SQL injection vulnerability in the loadMoreArticles endpoint due to improper vali...

2026-07-28
Full analysis →
CVE-2026-65766
Analyzed
9.2
joomshaper.com SP Page Builder extension for Joomla

The SP Page Builder extension for Joomla contains an unauthenticated SQL injection vulnerability in the Dynamic Content endpoint due to improper valid...

2026-07-28
Full analysis →
CVE-2026-65761
Analyzed
9.3
joomshaper.com Easy Store extension for Joomla

The Easy Store extension for Joomla is vulnerable to an unauthenticated SQL injection, allowing remote attackers to access database credentials and se...

2026-07-24
Full analysis →
CVE-2026-57830
Analyzed
8.8
joomshaper.com Helix Ultimate extension for Joomla

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion

2026-07-13
Full analysis →
CVE-2026-57829
Analyzed
8.7
joomshaper.com Helix Ultimate extension for Joomla

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS

2026-07-13
Full analysis →
CVE-2026-49049
Analyzed
7.5
joomshaper.com Helix3 extension for Joomla

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files...

2026-06-30
Full analysis →