What is CVE-2026-67287?
This vulnerability exists in the Joomla SP Page Builder extension (before version 6.8.0). An unauthenticated attacker can bypass the disabled guest commenting feature by overriding the setting with user-supplied input, allowing them to create comments. Updating SP Page Builder to at least version 6.8.0 is recommended to mitigate this issue.
Azərbaycanca: Bu boşluq Joomla SP Page Builder əlavəsində (6.8.0 versiyasından əvvəl) aşkarlanıb. Qonaq şərh yazmaq funksiyası deaktiv olduqda belə, autentifikasiya olunmamış hücumçu xüsusi daxiletmə ilə bu məhdudiyyəti keçərək şərh yaza bilir. Təsirə məruz qalmamaq üçün SP Page Builder-i ən azı 6.8.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: joomshaper.com
FAQ2
Which versions of the SP Page Builder extension are affected by CVE-2026-67287?
This vulnerability exists in all versions of SP Page Builder before version 6.8.0.
How can an attacker exploit CVE-2026-67287 even if the guest commenting feature is disabled?
An unauthenticated attacker can bypass the disabled setting by overriding it with user-supplied input, allowing them to create comments.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.