What is CVE-2026-65766?
CVE-2026-65766 is an unauthenticated SQL injection vulnerability in the SP Page Builder extension for Joomla (versions before 6.7.1). It arises from improper validation of order parameters in the Dynamic Content endpoint. Users must immediately update the extension to the latest version.
Azərbaycanca: CVE-2026-65766, Joomla üçün SP Page Builder əlavəsində (6.7.1 versiyasından əvvəl) autentifikasiya olunmamış SQL injection zəifliyidir. Bu, Dynamic Content endpoint-də order parametrlərinin düzgün yoxlanılmaması səbəbindən baş verir. İstifadəçilər əlavəni dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which Joomla extension is affected by CVE-2026-65766?
This vulnerability affects the SP Page Builder extension for Joomla in versions prior to 6.7.1.
What should users do to protect against CVE-2026-65766?
Users must immediately update the SP Page Builder extension to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.