CVE-2026-78083
nicheMissing CSRF protection in JoomShaper SP Property booking and contact endpoints
SP Property, a real-estate listing component for Joomla from JoomShaper, versions before 4.1.4, processed POST requests on its visitor booking (properties.booking) and agent contact form (agents.sendmail) endpoints without verifying Joomla session anti-CSRF tokens (CWE-352). An attacker can host a page or link that induces a visitor's or logged-in user's browser to silently submit forged POST requests to these endpoints; because no token check is performed, the requests are accepted regardless of origin. The practical impact is rated high for integrity: an attacker can inject fraudulent booking submissions or trigger contact/email sends through the site's mail (e.g., spam or spoofed messages to agents), though no confidentiality impact is expected. Any Joomla site running SP Property prior to 4.1.4 is affected. There is currently no known exploitation, no public proof-of-concept, and the issue is not in CISA's KEV; a fix was released in SP Property 4.1.4.
What to do: Upgrade SP Property to 4.1.4 or later, available from JoomShaper. Until updated, there is no built-in configuration mitigation, so review site logs for unexpected or forged POST submissions to the properties.booking and agents.sendmail endpoints and consider WAF rules or Joomla's CAPTCHA/token-hardening options as partial mitigations.
| JoomShaper (joomshaper.com) SP Property (Joomla extension) | all versions prior to 4.1.4 (< 4.1.4) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 - The visitor booking (properties.booking) and agent contact form submission (agents.sendmail) endpoints processed POST requests without verifying Joomla session anti-CSRF tokens.
- Ecosystems
- Joomla
- Weakness
- CWE-352
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.