AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-66494

HIGH · CVSS 8.7 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The SP Page Builder component for Joomla versions prior to 6.7.0 is vulnerable to unauthenticated stored cross-site scripting (XSS), allowing attackers to inject malicious JavaScript into the site's database through a single HTTP request. This script executes automatically in the browser of an administrator when they access the editor, potentially compromising the site and its data. Joomla site administrators and developers using affected versions should prioritize patching to mitigate this high-severity vulnerability.

CVE
CVE-2026-66494
Severity
HIGH
CVSS
8.7
EPSS
0.39%
Java

Original NVD Description

Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder editor, the JavaScript executes in their browser automatically..