CVE-2026-102426: Joomshaper.com SP Page Builder Pro Extension For Joomla
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Joomla Extension - joomshaper.com - Reflected XSS in the Dynamic Content Filter addon in SP Page Builder Pro 3.0.0 - 5.6.1p2 - The slider minimum and maximum values are taken from the dc_filter_<fieldId> request parameter, split on the delimiter "l-r", HTML-escaped inside the data-value attribute, and then echoed without escaping as the span element's text content. An unauthenticated attacker reflects arbitrary HTML or JavaScript into the rendered page through a crafted dc_filter_<fieldId> value.
Affected products
- Joomshaper.com SP Page Builder Pro Extension For Joomla: version 3.0.0 - 5.6.1p2 only
Published 2026-10-05. Last modified 2026-10-06.