CyberRota Analysis
AI-GeneratedThe SP Page Builder extension for Joomla versions prior to 6.7.1 is vulnerable to an authenticated arbitrary file deletion due to improper path validation and access control list (ACL) checks in its media manager. This flaw allows authenticated users to delete files, potentially leading to data loss or service disruption. Joomla administrators and users of the affected extension should prioritize updating to the latest version to mitigate this risk.
CVE
CVE-2026-65878
Severity
HIGH
CVSS
8.3
EPSS
0.33%
Original NVD Description
Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.