<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>joomshaper.com CVEs · CVE Brief</title>
    <link>https://cvebrief.com/archive/cves/vendor/joomshaper-com/</link>
    <atom:link href="https://cvebrief.com/feeds/vendor/joomshaper-com.xml" rel="self" type="application/rss+xml"/>
    <description>High and critical joomshaper.com vulnerabilities covered by CVE Brief, with independent analyst commentary.</description>
    <language>en-us</language>
    <lastBuildDate>Tue, 15 Sep 2026 12:00:00 GMT</lastBuildDate>
    <item>
      <title>CVE-2026-78375 · CVSS 8.6 · SP Page Builder</title>
      <link>https://cvebrief.com/cve/cve-2026-78375/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-joomshaper-com-CVE-2026-78375</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/joomshaper-com.png" medium="image" type="image/png"/>
      <pubDate>Tue, 15 Sep 2026 12:00:00 GMT</pubDate>
      <description>Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0 - plgContentSppagebuilder::onContentAfterSave() read jform[attribs][sppagebuilder_article_id] from the request and concatenated it dire Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-78082 · CVSS 9.3 · SP Property extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-78082/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-joomshaper-com-CVE-2026-78082</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/joomshaper-com.png" medium="image" type="image/png"/>
      <pubDate>Fri, 11 Sep 2026 12:00:00 GMT</pubDate>
      <description>An unauthenticated SQL injection vulnerability in the SP Property extension for Joomla allows remote attackers to extract sensitive database information via unsanitized query parameters. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-78302 · CVSS 8.6 · SP Property extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-78302/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-joomshaper-com-CVE-2026-78302</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/joomshaper-com.png" medium="image" type="image/png"/>
      <pubDate>Fri, 11 Sep 2026 12:00:00 GMT</pubDate>
      <description>Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property &lt; 4.1.4 - Multiple template files across frontend views and administrator list tables rendered attributes and text values directly in Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-78077 · CVSS 8.6 · Helix Ultimate extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-78077/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-joomshaper-com-CVE-2026-78077</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/joomshaper-com.png" medium="image" type="image/png"/>
      <pubDate>Tue, 01 Sep 2026 12:00:00 GMT</pubDate>
      <description>Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container &amp; Embed Inputs in Helix Ultimate &lt; 2.2.10 - Unsanitized column and item configuration values stored within the MegaMenu layout JSON were rendered without complete contextual escapin Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-78078 · CVSS 8.9 · Helix Ultimate extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-78078/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-joomshaper-com-CVE-2026-78078</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/joomshaper-com.png" medium="image" type="image/png"/>
      <pubDate>Tue, 01 Sep 2026 12:00:00 GMT</pubDate>
      <description>Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate &lt; 2.2.10 - Image uploads previously validated only file extension and basic size parameters. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-66494 · CVSS 8.7 · SP Page Builder extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-66494/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-joomshaper-com-CVE-2026-66494</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/joomshaper-com.png" medium="image" type="image/png"/>
      <pubDate>Sat, 08 Aug 2026 12:00:00 GMT</pubDate>
      <description>Joomla Extension - joomshaper Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-65766 · CVSS 9.2 · SP Page Builder extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-65766/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-joomshaper-com-CVE-2026-65766</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/joomshaper-com.png" medium="image" type="image/png"/>
      <pubDate>Tue, 28 Jul 2026 12:00:00 GMT</pubDate>
      <description>The SP Page Builder extension for Joomla contains an unauthenticated SQL injection vulnerability in the Dynamic Content endpoint due to improper validation of order parameters. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-65876 · CVSS 9.2 · SP Page Builder extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-65876/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-joomshaper-com-CVE-2026-65876</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/joomshaper-com.png" medium="image" type="image/png"/>
      <pubDate>Tue, 28 Jul 2026 12:00:00 GMT</pubDate>
      <description>The SP Page Builder extension for Joomla contains an unauthenticated SQL injection vulnerability in the loadMoreArticles endpoint due to improper validation of catid parameters. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-65877 · CVSS 8.2 · SP Page Builder extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-65877/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-joomshaper-com-CVE-2026-65877</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/joomshaper-com.png" medium="image" type="image/png"/>
      <pubDate>Tue, 28 Jul 2026 12:00:00 GMT</pubDate>
      <description>Joomla Extension - joomshaper Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-65878 · CVSS 8.3 · SP Page Builder extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-65878/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-joomshaper-com-CVE-2026-65878</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/joomshaper-com.png" medium="image" type="image/png"/>
      <pubDate>Tue, 28 Jul 2026 12:00:00 GMT</pubDate>
      <description>Joomla Extension - joomshaper Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-65759 · CVSS 8.7 · Easy Store extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-65759/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-joomshaper-com-CVE-2026-65759</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/joomshaper-com.png" medium="image" type="image/png"/>
      <pubDate>Fri, 24 Jul 2026 12:00:00 GMT</pubDate>
      <description>Joomla Extension - joomshaper Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-65761 · CVSS 9.3 · Easy Store extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-65761/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-joomshaper-com-CVE-2026-65761</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/joomshaper-com.png" medium="image" type="image/png"/>
      <pubDate>Fri, 24 Jul 2026 12:00:00 GMT</pubDate>
      <description>The Easy Store extension for Joomla is vulnerable to an unauthenticated SQL injection, allowing remote attackers to access database credentials and session data. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-57829 · CVSS 8.7 · Helix Ultimate extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-57829/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-joomshaper-com-CVE-2026-57829</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/joomshaper-com.png" medium="image" type="image/png"/>
      <pubDate>Mon, 13 Jul 2026 12:00:00 GMT</pubDate>
      <description>The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-57830 · CVSS 8.8 · Helix Ultimate extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-57830/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-joomshaper-com-CVE-2026-57830</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/joomshaper-com.png" medium="image" type="image/png"/>
      <pubDate>Mon, 13 Jul 2026 12:00:00 GMT</pubDate>
      <description>The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-49049 · CVSS 7.5 · Helix3 extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-49049/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-joomshaper-com-CVE-2026-49049</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/joomshaper-com.png" medium="image" type="image/png"/>
      <pubDate>Tue, 30 Jun 2026 12:00:00 GMT</pubDate>
      <description>The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters Independent analyst report on CVE Brief.</description>
    </item>
  </channel>
</rss>
