
CVE-2026-66494 Joomla Extension - http://joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaSc… https://www.cve.org/CVERecord?id=CVE-2026-66494
Post summary
The post announces a stored XSS vulnerability in the SP Page Builder extension for Joomla, providing its CVE ID and a brief technical description, but no PoC, exploit code, patch, or evidence of active exploitation.


