CVE-2026-78374
Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 - The front-end JSON editor endpoint exposes an action called contact that requires no authentication, no CSRF token, no captcha (when no captcha plugin is enabled) and has no rate limiting. The attacker fully controls the recipient, subject and HTML body, and the mail is sent from the site's configured sender identity (mailfrom/fromname).
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
- CWE
- CWE-201
- Published
- 2026-09-10
- Last modified
- 2026-09-10
Affected products
- joomlart.com T4 Page Builder extension for Joomla
Weakness type
Related vulnerabilities
- CVE-2026-81804 — WordPress ZHBackup – Backup, Restore & Migration plugin <= 2.4.2 - Sensitive Data Exposure vulnerability
- CVE-2026-78303 — Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4
- CVE-2026-87015 — Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication
- CVE-2026-65812 — Microsoft Teams for Android Information Disclosure Vulnerability
- CVE-2026-86505 — In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to...
- CVE-2026-86497 — In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed...
- CVE-2026-85307 — WordPress KP Agent Ready plugin < 1.2.08 - Sensitive Data Exposure vulnerability
- CVE-2026-77123 — Nexus Repository 3 - Webhook Secret Disclosure via Capability Read API