SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-78085

MEDIUM · CVSS 6.9 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A path traversal vulnerability exists in the Gallery Image Management feature of the SP Property Joomla extension, versions prior to 4.1.4, allowing attackers to access arbitrary files on the server. This could lead to unauthorized data exposure or manipulation, posing a risk to web applications utilizing this extension. Joomla administrators and developers using affected versions should prioritize applying the available updates to mitigate potential exploitation.

CVE
CVE-2026-78085
Severity
MEDIUM
CVSS
6.9
EPSS
0.36%

Original NVD Description

Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks.