CVSS
8.7
CVSS v4.0
EPSS
0.4%
Exploit Prediction Score
Published
August 7, 2026
Exploitability
EPSS probability 0.4%
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder editor, the JavaScript executes in their browser automatically..
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).