Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

joomshaper.com — Vulnerabilities & Security Advisories 11

Browse all 11 CVE security advisories affecting joomshaper.com. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates known security vulnerabilities associated with the vendor JoomShaper, focusing on weaknesses found in their Joomla extensions and related software products. The dataset compiles details on various security flaws, including SQL injection, cross-site scripting, and path traversal issues, covering reports published from 2018 through 2024. By organizing these entries, the resource allows users to track the historical advisory timeline of JoomShaper, providing insight into how the vendor responds to and remediates security incidents over time. Visitors can examine specific weakness classes to understand the technical impact and common attack vectors exploited in these systems. The collection also serves as a lookup tool for the complete vulnerability history of individual JoomShaper products, enabling developers and security auditors to assess the risk posture of specific extensions before deployment. This aggregation highlights patterns in code quality and security practices within the vendor’s portfolio, offering a clear view of past exposures and their resolutions. The information is presented to support informed decision-making regarding third-party component risks in web infrastructure. It does not provide live monitoring or real-time alerting but rather serves as a static reference for historical security data analysis. Users are encouraged to cross-reference this data with official vendor notices and current patch levels for the most accurate protection strategies.

CVE IDTitleCVSSSeverityPublished
CVE-2026-65876 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 — SP Page Builder extension for JoomlaCWE-89 9.2 Critical2026-07-27
CVE-2026-65877 Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 — SP Page Builder extension for JoomlaCWE-89 8.2 High2026-07-27
CVE-2026-65879 Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 — SP Page Builder extension for Joomla--2026-07-27
CVE-2026-65766 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 — SP Page Builder extension for JoomlaCWE-89 9.2 Critical2026-07-27
CVE-2026-65878 Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1 — SP Page Builder extension for JoomlaCWE-22 8.3 High2026-07-27
CVE-2026-65759 Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 — Easy Store extension for JoomlaCWE-284 8.7 High2026-07-23
CVE-2026-65761 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 — Easy Store extension for JoomlaCWE-89 9.3 Critical2026-07-23
CVE-2026-65760 Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 — Easy Store extension for JoomlaCWE-284 9.2 Critical2026-07-23
CVE-2026-57830 Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 — Helix Ultimate extension for JoomlaCWE-862 8.8 High2026-07-13
CVE-2026-57829 Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 — Helix Ultimate extension for JoomlaCWE-79 8.7 High2026-07-13
CVE-2026-49049 Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler — Helix3 extension for JoomlaCWE-284--2026-06-29

This page lists every published CVE security advisory associated with joomshaper.com. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.