CVE-2026-78374
Deferred Deferred - Pending Action

Open Mail Relay in T4 Page Builder Extension

Vulnerability report for CVE-2026-78374, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: Joomla! Project

Description

Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 - The front-end JSON editor endpoint exposes an action called contact that requires no authentication, no CSRF token, no captcha (when no captcha plugin is enabled) and has no rate limiting. The attacker fully controls the recipient, subject and HTML body, and the mail is sent from the site's configured sender identity (mailfrom/fromname).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
joomlart t4_page_builder to 2.3.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an open mail relay flaw in the T4 Page Builder Joomla extension versions below 2.3.0. The contact AJAX endpoint allows unauthenticated attackers to send emails with controlled recipient, subject, and HTML body. The emails appear to come from the site's configured sender identity, bypassing authentication, CSRF tokens, captchas, and rate limits.

Detection Guidance

Check Joomla extensions for T4 Page Builder versions below 2.3.0. Inspect server logs for unusual outbound SMTP traffic or JSON POST requests to /index.php?option=com_t4&task=contact. Monitor for unauthorized email sending from the site's configured sender identity.

Impact Analysis

Attackers could use your website to send spam or phishing emails, potentially damaging your reputation. Your server's IP might get blacklisted, affecting legitimate email delivery. The vulnerability could also be used for social engineering attacks impersonating your organization.

Compliance Impact

This vulnerability could lead to unauthorized data processing or disclosure, violating GDPR principles of lawfulness and transparency. For HIPAA, it might enable unauthorized transmission of protected health information. Both regulations require organizations to implement security measures to prevent such breaches.

Mitigation Strategies

Update T4 Page Builder to version 2.3.0 or higher immediately. Disable the contact AJAX endpoint if not required. Implement rate limiting and CSRF tokens for all forms. Enable captcha plugins to add additional security layers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78374. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart