AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-67285

CRITICAL · CVSS 9.2 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The SP Page Builder extension for Joomla versions prior to 6.8.0 is vulnerable to unauthenticated arbitrary local PHP file inclusion, allowing attackers to include and execute arbitrary PHP files on the server. This critical vulnerability could lead to complete system compromise, making it essential for all Joomla administrators using affected versions to prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-67285
Severity
CRITICAL
CVSS
9.2
EPSS
0.38%

Original NVD Description

Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbitrary PHP files that are accessible by the system.