CVE-2026-78374: Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0

Published Sep 10, 2026
·
Updated

Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 - The front-end JSON editor endpoint exposes an action called contact that requires no authentication, no CSRF token, no captcha (when no captcha plugin is enabled) and has no rate limiting. The attacker fully controls the recipient, subject and HTML body, and the mail is sent from the site's configured sender identity (mailfrom/fromname).

Affected Software

1 affected component
joomlart T4 Page Builder<2.3.0

Event History

Sep 10, 2026
CVE Published
via MITRE·10:01 AM
Data Sourced
via MITRE·10:01 AM
DescriptionWeakness

Frequently Asked Questions

1

Who is exposed to abuse through this endpoint?

Sites running T4 Page Builder versions earlier than 2.3.0 are exposed if the front-end JSON editor contact action is reachable. The endpoint does not require authentication or a CSRF token.

2

What does an attacker need to send mail through the site?

An attacker only needs to submit requests to the exposed contact action. They can choose the recipient, subject, and HTML body, and messages are sent using the site's configured sender address and name.

3

Does CAPTCHA prevent exploitation?

No CAPTCHA is required when no CAPTCHA plugin is enabled. The available information does not establish whether an enabled CAPTCHA plugin protects this endpoint.

4

What makes large-scale abuse likely?

The endpoint has no rate limiting, allowing repeated unauthenticated requests. This can enable bulk spam or phishing messages that appear to originate from the site's configured sender identity.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203