SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-78303

MEDIUM · CVSS 6.9 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Joomla Extension from joomshaper.com is vulnerable due to unvalidated email destination handling and form manipulation in SP Property versions prior to 4.1.4, which allows attackers to exploit hidden fields in booking inquiries for email routing. This could lead to unauthorized email redirection, potentially compromising sensitive information. Organizations using affected versions should prioritize patching to mitigate the risk of email manipulation attacks.

CVE
CVE-2026-78303
Severity
MEDIUM
CVSS
6.9
EPSS
0.25%

Original NVD Description

Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing potential email manipulation.