What is CVE-2026-65876?
CVE-2026-65876 is an unauthenticated SQL injection vulnerability affecting Joomla's SP Page Builder extension before version 6.7.1. Improper validation of the 'catid' parameter in the 'loadMoreArticles' endpoint creates an SQL injection vector. Users must update SP Page Builder to the latest patched version.
Azərbaycanca: CVE-2026-65876, Joomla-nın SP Page Builder plagininin 6.7.1-dən əvvəlki versiyalarına təsir edən, autentifikasiya tələb etməyən SQL injection zəifliyidir. 'loadMoreArticles' funksiyasında 'catid' parametrinin düzgün yoxlanılmaması səbəbindən yaranır. İstifadəçilər SP Page Builder-i ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: joomshaper.com
FAQ2
Which Joomla extension is affected by CVE-2026-65876?
CVE-2026-65876 affects the SP Page Builder extension for Joomla.
To which version should SP Page Builder be updated to mitigate CVE-2026-65876?
SP Page Builder should be updated to version 6.7.1 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.