What's new
  • The default language of any content posted is English.
    Do not create multi-accounts, you will be blocked! For more information about rules, limits, and more, visit the Help page.
    Found a dead link? Use the report button!

Sp Page Builder 6.6.2 - Critical Update

SP Page Builder version 6.7.1 is a critical security update released by JoomShaper on July 27, 2026. This release addresses several severe vulnerabilities that allow attackers to exploit exposed Joomla websites without requiring authentication. If you are running any earlier version of SP Page Builder, you must patch your site immediately. [1, 2, 3, 4]

Critical Vulnerabilities Fixed in 6.7.1
The security patch addresses multiple flaws, primarily discovered and tracked in late July 2026: [1]
  • CVE-2026-65766 (Unauthenticated SQL Injection): Improper input validation of order parameters in the Dynamic Content endpoint allowed unauthenticated attackers to manipulate database queries. Version 6.7.1 mitigates this by restricting parameters to safe values (ASC/DESC) and enforcing strict permission checks. [1, 2]
  • CVE-2026-65876 (Unauthenticated SQL Injection): A separate unauthenticated SQL injection vector targeting the loadMoreArticles endpoint. [1, 2]
  • CVE-2026-65879 (Unauthenticated Mail Relay): Attackers could leverage a hardcoded, product-wide secret key to forge "Mail From" addresses in forms, converting your Joomla server into a spam relay. [1]
  • CVE-2026-65877 (Authenticated SQL Injection): Inadequate parameter sanitization within the Media Manager search and date filters allowed authenticated users with privileges to execute malicious SQL queries. [1]
 
Reacted by:
  • Like
Reactions: Ahmed Hashim
Top