What is CVE-2026-65877?
CVE-2026-65877 is an authenticated SQL injection vulnerability in the SP Page Builder extension for Joomla, affecting versions prior to 6.7.1. The flaw exists due to improper validation of parameters in the media manager search and date filters. Users are advised to immediately update the SP Page Builder extension to the latest patched version.
Azərbaycanca: CVE-2026-65877, Joomla üçün SP Page Builder əlavəsində autentifikasiya olunmuş SQL injection zəifliyidir. Bu boşluq 6.7.1 versiyasından əvvəlki versiyalarda media menecerinin axtarış və tarix filtrlərindəki parametrlərin düzgün yoxlanılmaması səbəbindən yaranır. İstifadəçilərə dərhal SP Page Builder əlavəsini ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: joomshaper.com
FAQ1
Which versions of SP Page Builder are affected by CVE-2026-65877?
CVE-2026-65877 affects SP Page Builder versions prior to 6.7.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.