All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-67285
CRITICALpublished 2026-08-12 14:18 UTC · 13 hours ago · modified 2026-08-12 15:18 UTC
9.2
CVSS / 10
// description
Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbitrary PHP files that are accessible by the system.
// weaknesses (CWE)
- CWE-22