CVE-2026-67287: Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0
Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Joomla Extension - joomshaper.com - SP Page Builderto a version that resolves this vulnerability.Fixed in 6.8.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67287?
CVE-2026-67287 has a risk score of 30, indicating a significant vulnerability.
How do I fix CVE-2026-67287?
To fix CVE-2026-67287, update the JoomShaper SP Page Builder to version 6.8.0 or later.
What type of vulnerability is CVE-2026-67287?
CVE-2026-67287 is an unauthenticated comment creation vulnerability in the JoomShaper SP Page Builder.
Who is affected by CVE-2026-67287?
Instances of JoomShaper SP Page Builder versions below 6.8.0 are affected by CVE-2026-67287.
Can CVE-2026-67287 be exploited?
Yes, an unauthenticated attacker can exploit CVE-2026-67287 to create comments even when guest commenting is disabled.