CVE-2026-65766

JoomShaper · SP Page Builder

The SP Page Builder extension for Joomla contains an unauthenticated SQL injection vulnerability in the Dynamic Content endpoint due to improper validation of order parameters.

Executive summary

A critical unauthenticated SQL injection vulnerability in the JoomShaper SP Page Builder extension allows remote attackers to perform unauthorized database operations.

Vulnerability

This is an SQL injection vulnerability occurring within the Dynamic Content endpoint of the extension. The flaw permits an unauthenticated attacker to manipulate order parameters to inject arbitrary SQL commands.

Business impact

The ability for an unauthenticated attacker to execute arbitrary SQL commands poses a severe risk to data confidentiality and integrity. Successful exploitation could lead to the unauthorized extraction of sensitive database information, including user credentials or site configuration data, justifying the critical CVSS score of 9.2.

Remediation

Immediate Action: Update the SP Page Builder extension to version 6.7.1 or later immediately.

Proactive Monitoring: Review web server and database access logs for suspicious query patterns or unexpected SQL syntax errors originating from the Dynamic Content endpoint.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns until the update can be applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of this SQL injection flaw and the ease of access for unauthenticated attackers, administrators must prioritize updating the SP Page Builder extension to version 6.7.1. Failure to patch may result in total database compromise.