« Volver al listado

Joomshaper

Joomshaper SP Property: vulnerabilidades y CVE

Joomshaper SP Property tiene 6 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses6
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-78085Media (6.9)0.50%—10 sept 2026
Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks.
CVE-2026-78303Media (6.9)0.43%—10 sept 2026
Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient…
CVE-2026-78302Alta (8.6)0.44%—10 sept 2026
Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and…
CVE-2026-78084Media (6.9)0.33%—10 sept 2026
Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked authorization checks and CSRF token validation.. Users could…
CVE-2026-78083Alta (7.1)0.21%—10 sept 2026
Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 - The visitor booking (properties.booking) and agent contact form submission…
CVE-2026-78082Crítica (9.3)0.51%—10 sept 2026
Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1189 Drive-by Compromise2
  2. T1005 Data from Local System1
  3. T1059.007 JavaScript1
  4. T1190 Exploit Public-Facing Application1
  5. T1566.002 Spearphishing Link1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Joomshaper