CVE-2026-65879 Details
Description
Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.
A vulnerability in JoomShaper's SP Page Builder for Joomla, all versions prior to 6.7.1, allows for unauthenticated mail relay. This issue arises from a hardcoded secret that is identical across all copies of the extension, enabling attackers to forge the 'from' address of emails sent through contact forms. The vulnerability could be exploited to send emails with a spoofed sender, using the site's domain and mail server, effectively creating an open relay for spam and phishing.
Users are advised to update SP Page Builder to version 6.7.1. Instructions for updating can be found on the JoomShaper website or through the Joomla Extensions Manager. For those managing multiple sites, mySites.guru offers a mass update feature.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 27, 2026CISA-ADP
Assessed Jul 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://mysites.guru/blog/sp-page-builder-sql-injection-mail-relay-disclosure/ | [email protected] | BundleRemedyTechnical Analysis |
| https://www.joomshaper.com/page-builder | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| JoomShaper SP Page Builder | < 6.7.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 28, 2026 | CVE Modified | CISA-ADP |
| Jul 27, 2026 | New CVE Received | [email protected] |
Volerion