What's new
  • The default language of any content posted is English.
    Do not create multi-accounts, you will be blocked! For more information about rules, limits, and more, visit the Help page.
    Found a dead link? Use the report button!
SP Page Builder PRO - Drag and drop page composer for Joomla

SP Page Builder PRO - Drag and drop page composer for Joomla 6.3.0

SP Page Builder PRO v6.7.1

(27 July 2026)

Changelog:

Fixes
  • Improved input validation and access control on Dynamic Content's Tags sorting functionality.
  • Strengthened input validation on Media Manager's search and date filters.
  • Restricted Media Manager's file deletion action and added stricter access control.
  • Improved Contact Form and Form Builder submission verification.
  • Resolved an issue where the builtin security question check on Contact Form and Form Builder could be bypassed under certain conditions.
DOWNLOAD 👇
*** Hidden text: cannot be quoted. ***
Thanks for sharing this resource. I have been searching for this update.
 
Reacted by:
  • Like
Reactions: crc, madmax72 and GmbH
We found a pre-authentication remote code execution flaw in SP Page Builder, the page builder for Joomla by JoomShaper, and reported it privately to the developers.

An unauthenticated visitor could make the site run a PHP file of their choosing from anywhere on the filesystem. It sits in the same part of the component that the previous update, 6.7.1, was supposed to have secured. It is fixed in SP Page Builder 6.8.0.

If you run SP Page Builder, update now. mySites.guru already flags every connected site still on a vulnerable version. Full write-up on the blog.

https://mysites.guru/.../sp-page-builder-pre-auth-rce.../...
Download the fixed version here.
 

Attachments

  • com_sppagebuilder_pro_v6.8.0.zip
    5.7 MB · Views: 49
We found a pre-authentication remote code execution flaw in SP Page Builder, the page builder for Joomla by JoomShaper, and reported it privately to the developers.

An unauthenticated visitor could make the site run a PHP file of their choosing from anywhere on the filesystem. It sits in the same part of the component that the previous update, 6.7.1, was supposed to have secured. It is fixed in SP Page Builder 6.8.0.

If you run SP Page Builder, update now. mySites.guru already flags every connected site still on a vulnerable version. Full write-up on the blog.

https://mysites.guru/.../sp-page-builder-pre-auth-rce.../...
Download the fixed version here.
This is a time saving one. Thank you very much, Mr. Oluwapaul
 
rizalconsultingid 's signature
Reacted by:
  • Like
Reactions: Richardone

Version 6.8.0​

12 August 2026

New
  • Added multilingual support for EasyStore pages.
  • Added an option to set multiple recipient emails in the Form Builder addon.
Updates
  • Added an option to clear Page Hits directly from the page menu in both editors.
  • Added details and index page labels for Dynamic Content pages inside both editors.
  • Improved AcyMailing compatibility.
  • Loaded an alias at the addon root for improved EasyStore compatibility.
  • Added a Joomla 3 version guard to the installer script.
  • Added Copy, Paste, and Paste Style support for addons inside the Table addon.
  • Hardened input validation, file handling, and access checks across the component.
Fixes
  • Fixed an unauthenticated SQL injection in the article loading endpoint.
  • Fixed a broken access control issue in the Comment addon that allowed guests to post comments while anonymous comments were disabled.
  • Fixed sorting column issues when pagination is enabled in Dynamic Content.
  • Fixed character length validation and a silent submit failure in the multistep Form Builder.
  • Handled an edge case where a warning was showing in debug mode.
  • Added some missing language strings in the Comment addon.
 

Attachments

  • com_sppagebuilder_pro_v6.8.0.zip
    5.7 MB · Views: 73
Top-liked message: 11

Version 6.8.0​

12 August 2026

New
  • Added multilingual support for EasyStore pages.
  • Added an option to set multiple recipient emails in the Form Builder addon.
Updates
  • Added an option to clear Page Hits directly from the page menu in both editors.
  • Added details and index page labels for Dynamic Content pages inside both editors.
  • Improved AcyMailing compatibility.
  • Loaded an alias at the addon root for improved EasyStore compatibility.
  • Added a Joomla 3 version guard to the installer script.
  • Added Copy, Paste, and Paste Style support for addons inside the Table addon.
  • Hardened input validation, file handling, and access checks across the component.
Fixes
  • Fixed an unauthenticated SQL injection in the article loading endpoint.
  • Fixed a broken access control issue in the Comment addon that allowed guests to post comments while anonymous comments were disabled.
  • Fixed sorting column issues when pagination is enabled in Dynamic Content.
  • Fixed character length validation and a silent submit failure in the multistep Form Builder.
  • Handled an edge case where a warning was showing in debug mode.
  • Added some missing language strings in the Comment addon.
Thank you for Update Download the fixed version here.
 
New Version 6.9.0
  • Page lock indicator now shows who locked an SP Page Builder page, with the lock date and time on hover, matching Joomla's native behavior.
  • Added support for purging all unused page versions.
  • Added Mailchimp tag support to the Opt-in Form addon.
  • Added video support to the Gallery addon.
  • Added multilingual support for Details and Index pages.
  • Added changelog support for SP Page Builder Pro.
  • Added responsive support for custom image shapes.
Updates
  • Enforced TLS verification in opt-in form
  • Form Builder error messages now appear inline instead of using browser-default alerts.
Fixes
  • Fixed an issue where Article CSS was not cache-busted in production mode.
  • Fixed an issue where AVIF files were not visible in the Media Manager folder view.
  • Authenticated users with the 'core.create' permission could upload vulnerable SVG files.
  • Resolved an issue with SEF URL generation for nested dynamic content.
  • Resolved an issue with page CSS in article integration.
  • Resolved an issue with dynamic media aspect ratios when a custom type was selected
 
Last edited:
Top-liked message: 9
New Version 6.9.0
  • Page lock indicator now shows who locked an SP Page Builder page, with the lock date and time on hover, matching Joomla's native behavior.
  • Added support for purging all unused page versions.
  • Added Mailchimp tag support to the Opt-in Form addon.
  • Added video support to the Gallery addon.
  • Added multilingual support for Details and Index pages.
  • Added changelog support for SP Page Builder Pro.
  • Added responsive support for custom image shapes.
Updates
  • Enforced TLS verification in opt-in form
  • Form Builder error messages now appear inline instead of using browser-default alerts.
Fixes
  • Fixed an issue where Article CSS was not cache-busted in production mode.
  • Fixed an issue where AVIF files were not visible in the Media Manager folder view.
  • Authenticated users with the 'core.create' permission could upload vulnerable SVG files.
  • Resolved an issue with SEF URL generation for nested dynamic content.
  • Resolved an issue with page CSS in article integration.
  • Resolved an issue with dynamic media aspect ratios when a custom type was selected
*** Hidden text: cannot be quoted. ***

Thank you for Update Download
 
Reacted by:
New Version 6.9.0
  • Page lock indicator now shows who locked an SP Page Builder page, with the lock date and time on hover, matching Joomla's native behavior.
  • Added support for purging all unused page versions.
  • Added Mailchimp tag support to the Opt-in Form addon.
  • Added video support to the Gallery addon.
  • Added multilingual support for Details and Index pages.
  • Added changelog support for SP Page Builder Pro.
  • Added responsive support for custom image shapes.
Updates
  • Enforced TLS verification in opt-in form
  • Form Builder error messages now appear inline instead of using browser-default alerts.
Fixes
  • Fixed an issue where Article CSS was not cache-busted in production mode.
  • Fixed an issue where AVIF files were not visible in the Media Manager folder view.
  • Authenticated users with the 'core.create' permission could upload vulnerable SVG files.
  • Resolved an issue with SEF URL generation for nested dynamic content.
  • Resolved an issue with page CSS in article integration.
  • Resolved an issue with dynamic media aspect ratios when a custom type was selected
*** Hidden text: cannot be quoted. ***
Heey! Thanks a lot buddy!
 
Reacted by:
New Version 6.9.0
  • Page lock indicator now shows who locked an SP Page Builder page, with the lock date and time on hover, matching Joomla's native behavior.
  • Added support for purging all unused page versions.
  • Added Mailchimp tag support to the Opt-in Form addon.
  • Added video support to the Gallery addon.
  • Added multilingual support for Details and Index pages.
  • Added changelog support for SP Page Builder Pro.
  • Added responsive support for custom image shapes.
Updates
  • Enforced TLS verification in opt-in form
  • Form Builder error messages now appear inline instead of using browser-default alerts.
Fixes
  • Fixed an issue where Article CSS was not cache-busted in production mode.
  • Fixed an issue where AVIF files were not visible in the Media Manager folder view.
  • Authenticated users with the 'core.create' permission could upload vulnerable SVG files.
  • Resolved an issue with SEF URL generation for nested dynamic content.
  • Resolved an issue with page CSS in article integration.
  • Resolved an issue with dynamic media aspect ratios when a custom type was selected
*** Hidden text: cannot be quoted. ***
Cool. Thx! I like this comments
 
Reacted by:
Top