nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-67286 CVE-2026-67286
MEDIUM
Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0
Record summary
CVE-2026-67286 has a selected CVSS score of 6.3 (medium).
Description
Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 12, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SP Page Builder extension for JoomlaBrowse joomshaper.com / SP Page Builder extension for JoomlaDefault status: unaffected | CVE List | 1.0.0-6.7.1 | affected |
References
2joomshaper.comproduct
https://www.joomshaper.com/page-builder