SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65878

HIGH · CVSS 8.3 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The SP Page Builder extension for Joomla versions prior to 6.7.1 is vulnerable to an authenticated arbitrary file deletion due to improper path validation and access control list (ACL) checks in its media manager. This flaw allows authenticated users to delete files, potentially leading to data loss or service disruption. Joomla administrators and users of the affected extension should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-65878
Severity
HIGH
CVSS
8.3
EPSS
0.33%

Original NVD Description

Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.