SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-78083

HIGH · CVSS 7.1 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The SP Property extension for Joomla versions prior to 4.1.4 is vulnerable due to missing CSRF token verification in its booking and agent contact endpoints, allowing attackers to exploit this oversight. This could lead to unauthorized actions being executed on behalf of legitimate users, potentially compromising user data and site integrity. Joomla site administrators using this extension should prioritize applying the latest updates to mitigate this high-severity vulnerability.

CVE
CVE-2026-78083
Severity
HIGH
CVSS
7.1
EPSS
0.21%

Original NVD Description

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 - The visitor booking (properties.booking) and agent contact form submission (agents.sendmail) endpoints processed POST requests without verifying Joomla session anti-CSRF tokens.