CVE-2026-78084

Summary

Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked authorization checks and CSRF token validation.. Users could invoke file removal actions with arbitrary path strings or upload unverified file types.

Affected Software

VendorProductVersion RangeStatus
joomshaper.comSP Property extension for Joomla1.0.0-4.1.3affected

Weaknesses

  • CWE-284: CWE-284 Improper Access Control
  • CWE-352: CWE-352 Cross-Site Request Forgery (CSRF)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References