cbcvebase.

Joomshaper.Com Sp Property Extension For Joomla vulnerabilities

6 known vulnerabilities affecting joomshaper.com/sp_property_extension_for_joomla.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2026-78082P2CRITICALCVSS 9.3v1.0.0-4.1.32026-09-10
CVE-2026-78082 [CRITICAL] CWE-89 CVE-2026-78082: Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filteri Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting, price_range_dropdown, and psize_range_dropdown) by directly concatenating raw request parameters into SQL strin
nvd
CVE-2026-78084P3MEDIUMCVSS 6.9v1.0.0-4.1.32026-09-10
CVE-2026-78084 [MEDIUM] CWE-284 CVE-2026-78084: Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Propert Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked authorization checks and CSRF token validation.. Users could invoke file removal actions with arbitrary path strings or upload unverified file types.
nvd
CVE-2026-78302P3HIGHCVSS 8.6v1.0.0-4.1.32026-09-10
CVE-2026-78302 [HIGH] CWE-79 CVE-2026-78302: Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and administrator list tables rendered attributes and text values directly into HTML without contextual escaping.
nvd
CVE-2026-78085P3MEDIUMCVSS 6.9v1.0.0-4.1.32026-09-10
CVE-2026-78085 [MEDIUM] CWE-22 CVE-2026-78085: Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1. Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks.
nvd
CVE-2026-78303P3MEDIUMCVSS 6.9v1.0.0-4.1.32026-09-10
CVE-2026-78303 [MEDIUM] CWE-201 CVE-2026-78303: Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Req Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing potential email manipulation.
nvd
CVE-2026-78083P4HIGHCVSS 7.1v1.0.0-4.1.32026-09-10
CVE-2026-78083 [HIGH] CWE-352 CVE-2026-78083: Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Co Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 - The visitor booking (properties.booking) and agent contact form submission (agents.sendmail) endpoints processed POST requests without verifying Joomla session anti-CSRF tokens.
nvd
Joomshaper.Com Sp Property Extension For Joomla vulnerabilities | cvebase