CVE-2026-78082
A Joomla extension called SP Property has a critical SQL injection flaw that lets attackers read data from the database without authentication. The flaw exists in versions older than 4.1.4. Attackers can use the vulnerability to extract sensitive information.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Joomla SP Property extension versions older than 4.1.4, used by Joomla website owners.
Real-world impact
An attacker could read or manipulate database contents, potentially exposing personal data, financial information, or compromising the site.
Why this severity
The CVSS score of 9.3 reflects the high impact of the vulnerability: it allows attackers to read sensitive data with no authentication or special privileges, making it a critical risk.
What to do about it
- 01Upgrade the SP Property extension to version 4.1.4 or later.
NVD description
Timeline
- Sep 10, 2026 · 5d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 10, 2026 · 5d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.