← Back to the live CVE advisory feed

CVE-2026-78082: SP Property extension for Joomla

Severity
9.3 (CRITICAL)
Vendor
JOOMLA
Affected versions
1.0.0-4.1.3
Patch status
Unknown
Published
2026-09-10T10:17:31.863
Modified
2026-09-10T10:17:31.863

Why it matters

This matters because the affected product may be exploitable without valid credentials. Internet-facing deployments should be reviewed first.

Recommended admin actions

  • Prioritize validation immediately due to critical CVSS severity.
  • Treat internet-facing systems as higher priority.
  • Review logs for suspicious activity related to the affected application or component.

Technical summary

Joomla Extension – joomshaper.com – Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 – The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting, price_range_dropdown, and psize_range_dropdown) by directly concatenating raw request parameters into SQL strings without quoting or type casting. An unauthenticated remote attacker could execute boolean-based or time-based blind SQL injection to extract sensitive data from the database.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 10, 2026 12:00 PM UTC
345 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-67401
cPanel
Reporter: SUPPORT
9.9
CRITICAL
VIEW RECORD
CVE-2026-19583
Velociraptor
Reporter: CVE
9.9
CRITICAL
VIEW RECORD
CVE-2026-80172
secure connect gateway PATCH
Reporter: SECURITY_ALERT
9.8
CRITICAL
VIEW RECORD
CVE-2026-85102
Quantum Security Gateway
Reporter: CVE
9.8
CRITICAL
VIEW RECORD
CVE-2026-85103
Quantum Security Gateway
Reporter: CVE
9.8
CRITICAL
VIEW RECORD
CVE-2026-18351
Drag and Drop File Upload for Elementor Forms
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-7188
Access Control System
Reporter: ILETISIM
9.8
CRITICAL
VIEW RECORD
CVE-2026-88278
GV-LPCLPC2011/2211 PATCH
Reporter: 0DF08A0E-A200-4957-9BB0-084F562506F9
9.8
CRITICAL
VIEW RECORD
CVE-2026-54694
skills-service PATCH
Reporter: SECURITY-ADVISORIES
9.6
CRITICAL
VIEW RECORD
CVE-2026-44950
Container suse/kiosk/tigervnc-x11vnc:1.14-63.8
Reporter: MEISSNER
9.5
CRITICAL
VIEW RECORD
CVE-2026-88285
GV-LPC2011/LPC2211 PATCH
Reporter: 0DF08A0E-A200-4957-9BB0-084F562506F9
9.4
CRITICAL
VIEW RECORD
CVE-2026-47156
mantisbt
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-87929
MaxSite CMS
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-88069
pandora
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
9.3
CRITICAL
VIEW RECORD
CVE-2026-8323
Access Control System
Reporter: ILETISIM
9.3
CRITICAL
VIEW RECORD
CVE-2026-78082
SP Property extension for Joomla
Reporter: SECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-87930
MaxSite CMS
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-13745
Gemini CLI
Reporter: F45CBF4E-4146-4068-B7E1-655FFC2C548C
9.2
CRITICAL
VIEW RECORD
CVE-2026-59679
Container suse/kiosk/tigervnc-x11vnc:1.14-63.8
Reporter: MEISSNER
9.2
CRITICAL
VIEW RECORD
CVE-2026-87806
parse-server PATCH
Reporter: DISCLOSURE
9.1
CRITICAL
VIEW RECORD
CVE-2026-22590
Fast-DDS PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-67403
Sage AR Automation
Reporter: SUPPORT
9
CRITICAL
VIEW RECORD
CVE-2026-68484
Sage AR Automation
Reporter: SUPPORT
9
CRITICAL
VIEW RECORD
CVE-2026-87911
AWS Labs postgres MCP Server PATCH
Reporter: FF89BA41-3AA1-4D27-914A-91399E9639E5
9
CRITICAL
VIEW RECORD
CVE-2026-86099
chainlit
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-86775
Product identification pending PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-87823
Product identification pending PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-80914
Linux PATCH
Reporter: 416BAAA9-DC9F-4396-8D5F-8C081FB06D67
8.8
HIGH
VIEW RECORD
CVE-2026-80921
Linux PATCH
Reporter: 416BAAA9-DC9F-4396-8D5F-8C081FB06D67
8.8
HIGH
VIEW RECORD
CVE-2026-87927
Product identification pending
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-88271
GV-LPC2011/LPC2211 PATCH
Reporter: 0DF08A0E-A200-4957-9BB0-084F562506F9
8.8
HIGH
VIEW RECORD
CVE-2026-88277
GV-LPCLPC2011/2211 PATCH
Reporter: 0DF08A0E-A200-4957-9BB0-084F562506F9
8.8
HIGH
VIEW RECORD
CVE-2026-87807
siyuan PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-87808
siyuan PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-87816
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-87817
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-87819
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2023-54355
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2023-54390
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2023-54393
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2024-58381
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2024-58382
commonmark PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-86199
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-86201
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-87822
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-87824
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-81640
Product identification pending
Reporter: ICS-CERT
8.7
HIGH
VIEW RECORD
CVE-2026-77120
PowerLogic T300
Reporter: CYBERSECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-87995
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-87962
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-56711
VLC media player
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-86762
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-86770
snipe-it PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-26212
Rara One Click Demo Import PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-19233
EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert)
Reporter: CYBERSECURITY
8.6
HIGH
VIEW RECORD
CVE-2026-8044
EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert)
Reporter: CYBERSECURITY
8.6
HIGH
VIEW RECORD
CVE-2026-79322
Product identification pending
Reporter: CVE
8.6
HIGH
VIEW RECORD
CVE-2026-87931
Pavlok Behavioral Conditioning Wearable
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-78302
Product identification pending
Reporter: SECURITY
8.6
HIGH
VIEW RECORD
CVE-2026-86754
snipe-it PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-77974
Product identification pending
Reporter: ICS-CERT
8.5
HIGH
VIEW RECORD
CVE-2026-84063
Product identification pending
Reporter: VULTURES
8.5
HIGH
VIEW RECORD
CVE-2026-87811
siyuan PATCH
Reporter: DISCLOSURE
8.4
HIGH
VIEW RECORD
CVE-2026-87813
siyuan PATCH
Reporter: DISCLOSURE
8.4
HIGH
VIEW RECORD
CVE-2026-87814
siyuan PATCH
Reporter: DISCLOSURE
8.4
HIGH
VIEW RECORD
CVE-2026-87815
siyuan PATCH
Reporter: DISCLOSURE
8.4
HIGH
VIEW RECORD
CVE-2026-86741
Product identification pending PATCH
Reporter: DISCLOSURE
8.4
HIGH
VIEW RECORD
CVE-2026-86751
Product identification pending PATCH
Reporter: DISCLOSURE
8.4
HIGH
VIEW RECORD
CVE-2026-82563
Product identification pending
Reporter: ICS-CERT
8.4
HIGH
VIEW RECORD
CVE-2026-42805
Product identification pending
Reporter: PSIRT
8.4
HIGH
VIEW RECORD
CVE-2026-86750
Product identification pending PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-86771
Product identification pending PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-18147
Product identification pending
Reporter: SECALERT
8.1
HIGH
VIEW RECORD
CVE-2026-87874
Product identification pending
Reporter: SECALERT
8.1
HIGH
VIEW RECORD
CVE-2026-87016
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-14873
Bulk Password Reset
Reporter: SECURITY
8
HIGH
VIEW RECORD
CVE-2026-42807
Product identification pending
Reporter: PSIRT
8
HIGH
VIEW RECORD
CVE-2026-84042
Product identification pending
Reporter: SECALERT
7.8
HIGH
VIEW RECORD
CVE-2026-79637
secure connect gateway PATCH
Reporter: SECURITY_ALERT
7.7
HIGH
VIEW RECORD
CVE-2026-15140
Product identification pending
Reporter: PSIRT
7.7
HIGH
VIEW RECORD
CVE-2026-15913
Product identification pending PATCH
Reporter: DF4DEE71-DE3A-4139-9588-11B62FE6C0FF
7.7
HIGH
VIEW RECORD
CVE-2026-87996
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.7
HIGH
VIEW RECORD
CVE-2026-19584
Product identification pending
Reporter: CVE
7.7
HIGH
VIEW RECORD
CVE-2026-42804
Product identification pending
Reporter: PSIRT
7.6
HIGH
VIEW RECORD
CVE-2026-78490
secure connect gateway PATCH
Reporter: SECURITY_ALERT
7.5
HIGH
VIEW RECORD
CVE-2026-79738
secure connect gateway PATCH
Reporter: SECURITY_ALERT
7.5
HIGH
VIEW RECORD
CVE-2026-79740
secure connect gateway PATCH
Reporter: SECURITY_ALERT
7.5
HIGH
VIEW RECORD
CVE-2026-79950
secure connect gateway PATCH
Reporter: SECURITY_ALERT
7.5
HIGH
VIEW RECORD
CVE-2026-22591
Fast-DDS
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-80924
Linux PATCH
Reporter: 416BAAA9-DC9F-4396-8D5F-8C081FB06D67
7.5
HIGH
VIEW RECORD
CVE-2026-87853
Product identification pending
Reporter: SECALERT
7.5
HIGH
VIEW RECORD
CVE-2026-79323
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-73786
Product identification pending
Reporter: SECURITY-ALERT
7.5
HIGH
VIEW RECORD
CVE-2026-79324
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-87011
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-15019
Direct Download for WooCommerce
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-88286
GV-LPC2011/LPC2211 PATCH
Reporter: 0DF08A0E-A200-4957-9BB0-084F562506F9
7.5
HIGH
VIEW RECORD
CVE-2026-88287
GV-LPC2011/LPC2211 PATCH
Reporter: 0DF08A0E-A200-4957-9BB0-084F562506F9
7.5
HIGH
VIEW RECORD
CVE-2026-88289
GV-LPC2011/LPC2211 PATCH
Reporter: 0DF08A0E-A200-4957-9BB0-084F562506F9
7.5
HIGH
VIEW RECORD
CVE-2026-88290
GV-LPC2011/LPC2211 PATCH
Reporter: 0DF08A0E-A200-4957-9BB0-084F562506F9
7.5
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.