Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.3) | — | — | Joomshaper SP Page Builder PROAI | 5/10/2026 | 5/10/2026 | Joomla Extension - joomshaper.com - Reflected XSS in the Dynamic Content Filter addon in SP Page Builder Pro 3.0.0 - 5.6.1p2 - The slider minimum and maximum values are taken from the dc_filter_<fieldId> request parameter, split on the delimiter "l-r", HTML-escaped inside the data-value attribute, and then echoed… | |
| Aplazada | Media (5.1) | 0.39% | — | Joomshaper SP Page BuilderAI | 14/9/2026 | 16/9/2026 | Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The add-to-menu routine invoked the com_menus item model's save() method directly. That model does not perform authorisation itself, because the relevant checks reside in the com_menus… | |
| Aplazada | Media (6.9) | 0.47% | — | Joomshaper SP Page BuilderAI | 14/9/2026 | 16/9/2026 | Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The folder request parameter replaced the generated date-based destination folder in its entirety and was then passed to Folder::create() and File::upload() without either of the… | |
| Aplazada | Alta (7) | 0.47% | — | Joomshaper SP Page BuilderAI | 14/9/2026 | 16/9/2026 | Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The media rename task applied neither of the directory boundary checks used by the folder operations in the same controller, and its validation guard… | |
| Aplazada | Media (6.9) | 0.45% | — | Joomshaper SP Page Builder PROAI | 14/9/2026 | 16/9/2026 | Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 - The optin_form addon read the CAPTCHA type, the expected answer and the enabled flag from the request rather than from the stored addon configuration. Verification… | |
| Aplazada | Alta (8.6) | 0.37% | — | Joomla SP Page BuilderAIJoomshaper SP Page BuilderAI | 14/9/2026 | 16/9/2026 | Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0 - plgContentSppagebuilder::onContentAfterSave() read jform[attribs][sppagebuilder_article_id] from the request and concatenated it directly into the WHERE view_id = ...… | |
| Aplazada | Media (6.9) | 0.45% | — | Joomshaper SP Page Builder PROAIJoomlaAI | 14/9/2026 | 5/10/2026 | Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 5.6.1p2 and 6.0.0 - 6.9.0 - In the ajax_contact, optin_form and form_builder addons, the result returned by the CAPTCHA plugin's onCheckAnswer event was… | |
| Aplazada | Media (6.3) | 0.42% | — | Joomshaper SP Page BuilderAI | 12/8/2026 | 26/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input. | |
| Aplazada | Media (6.3) | 0.52% | — | Joomshaper SP Page BuilderAI | 12/8/2026 | 26/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name. | |
| Aplazada | Crítica (9.2) | 0.51% | — | Joomshaper SP Page BuilderAI | 12/8/2026 | 26/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbitrary PHP files that are accessible by the system. | |
| Aplazada | Alta (8.7) | 0.50% | — | Joomshaper SP Page BuilderAI | 7/8/2026 | 26/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder editor, the JavaScript executes in their… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Joomshaper SP Page BuilderAI | 27/7/2026 | 28/7/2026 | Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms. | |
| Aplazada | Alta (8.3) | 0.49% | — | JoomlaAIOllyo SP Page BuilderAI | 27/7/2026 | 27/7/2026 | Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager. | |
| Aplazada | Alta (8.2) | 0.38% | — | Joomshaper SP Page BuilderAI | 27/7/2026 | 27/7/2026 | Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector. | |
| Aplazada | Crítica (9.2) | 0.39% | — | Joomshaper SP Page BuilderAI | 27/7/2026 | 12/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector. | |
| Aplazada | Crítica (9.2) | 0.40% | — | Joomshaper SP Page BuilderAI | 27/7/2026 | 27/7/2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector. | |
| Analizada | Crítica (10) | 89% | ⚠ Explotación activa | Ollyo SP Page Builder | 20/6/2026 | 8/7/2026 | A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. |