CVE-2026-79700
Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 - The optin_form addon read the CAPTCHA type, the expected answer and the enabled flag from the request rather than from the stored addon configuration. Verification reduced to md5($captcha_question) != $captcha_answer with both operands supplied by the attacker, so any value passed.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.27%
- CWE
- CWE-807
- Published
- 2026-09-14
- Last modified
- 2026-09-15
Affected products
- joomshaper.com SP Page Builder (Pro) extension for Joomla
Weakness type
Related vulnerabilities
- CVE-2023-45128 — CSRF Token Reuse Vulnerability in fiber
- CVE-2025-66570 — cpp-httplib Untrusted HTTP Header Handling: Internal Header Shadowing (REMOTE*/LOCAL*)
- CVE-2025-12488 — oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability
- CVE-2025-12487 — oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability
- CVE-2026-87479 — Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had
- CVE-2025-55736 — flaskBlog allows arbitrary privilege escalation
- CVE-2025-1126 — Lexmark has identified a vulnerability in our Lexmark Print Management Client (LPMC).
- CVE-2024-51561 — Authentication bypass Vulnerability in Aero