AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-67287

MEDIUM · CVSS 6.3 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The SP Page Builder extension for Joomla versions prior to 6.8.0 is vulnerable to unauthenticated comment creation, allowing attackers to bypass guest commenting restrictions by manipulating input. This could lead to spam or malicious content being injected into the site, potentially damaging its reputation and user trust. Joomla site administrators using this extension should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-67287
Severity
MEDIUM
CVSS
6.3
EPSS
0.30%

Original NVD Description

Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input.