Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1
Summary
| CVE | CVE-2026-65879 |
| State | PUBLISHED |
| Assigner | Joomla |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-27 14:17:01 UTC |
| Updated | 2026-07-27 20:32:11 UTC |
| Description | Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms. |
Vendor Declared Affected Products
Vendor Comments And Credit
Discovery Credit
CNA: Phil Taylor (en)
There are currently no legacy QID mappings associated with this CVE.