PT-2026-64911 · Joomla · Wp Page Builder

CVE-2026-65876

·

Published

2026-07-27

·

Updated

2026-08-10

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions SP Page Builder versions prior to 6.7.1
Description An unauthenticated SQL injection exists due to improper validation of the catid parameter within the 'loadMoreArticles' endpoint. SQL injection is a technique where an attacker inserts malicious SQL code into a query, allowing them to manipulate the database.
Recommendations Update to version 6.7.1 or later. Avoid using the catid parameter in the 'loadMoreArticles' endpoint until the update is applied.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65876

Affected Products

Wp Page Builder