SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-65879

CRITICAL · CVSS 9.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The SP Page Builder extension for Joomla versions prior to 6.7.1 contains a critical vulnerability due to a hardcoded secret, enabling unauthenticated attackers to exploit the mail relay functionality and forge the sender's email address in forms. This could lead to phishing attacks or the distribution of malicious content under the guise of legitimate communications. Joomla site administrators and developers using this extension should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-65879
Severity
CRITICAL
CVSS
9.8
EPSS
0.28%

Original NVD Description

Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.