CVE-2026-67287

Summary

Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input.

Affected Software

VendorProductVersion RangeStatus
joomshaper.comSP Page Builder extension for Joomla1.0.0-6.7.1affected

Weaknesses

  • CWE-284: CWE-284 Improper Access Control

References