What's new
  • The default language of any content posted is English.
    Do not create multi-accounts, you will be blocked! For more information about rules, limits, and more, visit the Help page.
    Found a dead link? Use the report button!
SP Page Builder PRO - Drag and drop page composer for Joomla

SP Page Builder PRO - Drag and drop page composer for Joomla 6.3.0

SP Page Builder PRO v6.7.1

(27 July 2026)

Changelog:

Fixes
  • Improved input validation and access control on Dynamic Content's Tags sorting functionality.
  • Strengthened input validation on Media Manager's search and date filters.
  • Restricted Media Manager's file deletion action and added stricter access control.
  • Improved Contact Form and Form Builder submission verification.
  • Resolved an issue where the builtin security question check on Contact Form and Form Builder could be bypassed under certain conditions.
DOWNLOAD 👇
*** Hidden text: cannot be quoted. ***
Thanks for sharing this resource. I have been searching for this update.
 
Reacted by:
  • Like
Reactions: crc, madmax72 and GmbH
We found a pre-authentication remote code execution flaw in SP Page Builder, the page builder for Joomla by JoomShaper, and reported it privately to the developers.

An unauthenticated visitor could make the site run a PHP file of their choosing from anywhere on the filesystem. It sits in the same part of the component that the previous update, 6.7.1, was supposed to have secured. It is fixed in SP Page Builder 6.8.0.

If you run SP Page Builder, update now. mySites.guru already flags every connected site still on a vulnerable version. Full write-up on the blog.

https://mysites.guru/.../sp-page-builder-pre-auth-rce.../...
Download the fixed version here.
 

Attachments

  • com_sppagebuilder_pro_v6.8.0.zip
    5.7 MB · Views: 18
We found a pre-authentication remote code execution flaw in SP Page Builder, the page builder for Joomla by JoomShaper, and reported it privately to the developers.

An unauthenticated visitor could make the site run a PHP file of their choosing from anywhere on the filesystem. It sits in the same part of the component that the previous update, 6.7.1, was supposed to have secured. It is fixed in SP Page Builder 6.8.0.

If you run SP Page Builder, update now. mySites.guru already flags every connected site still on a vulnerable version. Full write-up on the blog.

https://mysites.guru/.../sp-page-builder-pre-auth-rce.../...
Download the fixed version here.
This is a time saving one. Thank you very much, Mr. Oluwapaul
 
rizalconsultingid 's signature
Reacted by:

Version 6.8.0​

12 August 2026

New
  • Added multilingual support for EasyStore pages.
  • Added an option to set multiple recipient emails in the Form Builder addon.
Updates
  • Added an option to clear Page Hits directly from the page menu in both editors.
  • Added details and index page labels for Dynamic Content pages inside both editors.
  • Improved AcyMailing compatibility.
  • Loaded an alias at the addon root for improved EasyStore compatibility.
  • Added a Joomla 3 version guard to the installer script.
  • Added Copy, Paste, and Paste Style support for addons inside the Table addon.
  • Hardened input validation, file handling, and access checks across the component.
Fixes
  • Fixed an unauthenticated SQL injection in the article loading endpoint.
  • Fixed a broken access control issue in the Comment addon that allowed guests to post comments while anonymous comments were disabled.
  • Fixed sorting column issues when pagination is enabled in Dynamic Content.
  • Fixed character length validation and a silent submit failure in the multistep Form Builder.
  • Handled an edge case where a warning was showing in debug mode.
  • Added some missing language strings in the Comment addon.
 

Attachments

  • com_sppagebuilder_pro_v6.8.0.zip
    5.7 MB · Views: 6
Reacted by:
  • Like
Reactions: natec and Monrim

Version 6.8.0​

12 August 2026

New
  • Added multilingual support for EasyStore pages.
  • Added an option to set multiple recipient emails in the Form Builder addon.
Updates
  • Added an option to clear Page Hits directly from the page menu in both editors.
  • Added details and index page labels for Dynamic Content pages inside both editors.
  • Improved AcyMailing compatibility.
  • Loaded an alias at the addon root for improved EasyStore compatibility.
  • Added a Joomla 3 version guard to the installer script.
  • Added Copy, Paste, and Paste Style support for addons inside the Table addon.
  • Hardened input validation, file handling, and access checks across the component.
Fixes
  • Fixed an unauthenticated SQL injection in the article loading endpoint.
  • Fixed a broken access control issue in the Comment addon that allowed guests to post comments while anonymous comments were disabled.
  • Fixed sorting column issues when pagination is enabled in Dynamic Content.
  • Fixed character length validation and a silent submit failure in the multistep Form Builder.
  • Handled an edge case where a warning was showing in debug mode.
  • Added some missing language strings in the Comment addon.
Thank you for Update Download the fixed version here.
 
Reacted by:
Top