What's new
  • The default language of any content posted is English.
    Do not create multi-accounts, you will be blocked! For more information about rules, limits, and more, visit the Help page.
    Found a dead link? Use the report button!
SP Page Builder PRO - Drag and drop page composer for Joomla

SP Page Builder PRO - Drag and drop page composer for Joomla 6.3.0

SP Page Builder PRO v6.7.1

(27 July 2026)

Changelog:

Fixes
  • Improved input validation and access control on Dynamic Content's Tags sorting functionality.
  • Strengthened input validation on Media Manager's search and date filters.
  • Restricted Media Manager's file deletion action and added stricter access control.
  • Improved Contact Form and Form Builder submission verification.
  • Resolved an issue where the builtin security question check on Contact Form and Form Builder could be bypassed under certain conditions.
DOWNLOAD 👇
*** Hidden text: cannot be quoted. ***
Thanks for sharing this resource. I have been searching for this update.
 
Reacted by:
  • Like
Reactions: crc, madmax72 and GmbH
We found a pre-authentication remote code execution flaw in SP Page Builder, the page builder for Joomla by JoomShaper, and reported it privately to the developers.

An unauthenticated visitor could make the site run a PHP file of their choosing from anywhere on the filesystem. It sits in the same part of the component that the previous update, 6.7.1, was supposed to have secured. It is fixed in SP Page Builder 6.8.0.

If you run SP Page Builder, update now. mySites.guru already flags every connected site still on a vulnerable version. Full write-up on the blog.

https://mysites.guru/.../sp-page-builder-pre-auth-rce.../...
Download the fixed version here.
 

Attachments

  • com_sppagebuilder_pro_v6.8.0.zip
    5.7 MB · Views: 18
Reacted by:
  • Like
Reactions: rizalconsultingid, weezle and MX2004
We found a pre-authentication remote code execution flaw in SP Page Builder, the page builder for Joomla by JoomShaper, and reported it privately to the developers.

An unauthenticated visitor could make the site run a PHP file of their choosing from anywhere on the filesystem. It sits in the same part of the component that the previous update, 6.7.1, was supposed to have secured. It is fixed in SP Page Builder 6.8.0.

If you run SP Page Builder, update now. mySites.guru already flags every connected site still on a vulnerable version. Full write-up on the blog.

https://mysites.guru/.../sp-page-builder-pre-auth-rce.../...
Download the fixed version here.
This is a time saving one. Thank you very much, Mr. Oluwapaul
 
rizalconsultingid 's signature
Reacted by:
Top