CVE-2026-67285: Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0
Published Aug 12, 2026
·Updated
Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbitrary PHP files that are accessible by the system.
Affected Software
1 affected component
SP Page Builder<6.8.0
Event History
Aug 12, 2026
CVE Published
via MITRE·01:54 PM
Data Sourced
via MITRE·01:54 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-67285?
CVE-2026-67285 has a risk score of 76, indicating a high severity vulnerability.
2
How do I fix CVE-2026-67285?
To fix CVE-2026-67285, upgrade SP Page Builder to version 6.8.0 or later.
3
What type of attack is possible with CVE-2026-67285?
CVE-2026-67285 allows unauthenticated attackers to perform arbitrary local PHP file inclusions.
4
Which software is affected by CVE-2026-67285?
CVE-2026-67285 affects the SP Page Builder extension for Joomla.
5
Is user authentication required to exploit CVE-2026-67285?
No, CVE-2026-67285 can be exploited without user authentication.