What is CVE-2026-66494?
CVE-2026-66494 is an unauthenticated stored XSS vulnerability in the Shapes API endpoint of the SP Page Builder Joomla extension (before version 6.7.0). An attacker can inject malicious JavaScript into the site's database via a single HTTP request, which executes when an administrator opens the SP Page Builder editor. Immediate update to the latest version is recommended.
Azərbaycanca: CVE-2026-66494, SP Page Builder Joomla genişləndirilməsinin (<6.7.0) Shapes API-sində autentifikasiya olmadan stored XSS zəifliyidir. Təcavüzkar xüsusi HTTP sorğu ilə verilənlər bazasına zərərli JavaScript yaza bilir, bu skript administrator SP Page Builder redaktorunu açanda icra olunur. Dərhal SP Page Builder-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
In which component of SP Page Builder is CVE-2026-66494 located?
The vulnerability is located in the Shapes API endpoint.
How can an attacker execute malicious code using this vulnerability?
An attacker injects malicious JavaScript into the database via a single HTTP request. This script executes when an administrator opens the SP Page Builder editor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.