Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

JoomShaper fixes critical SP Page Builder flaw

JoomShaper has fixed two unauthenticated vulnerabilities in SP Page Builder for Joomla, including a critical flaw that could enable remote code execution. Version 6.8.0 contains the fixes.

The issues affect SP Page Builder releases from 5.5.0 through 6.7.1. The extension's vendor, JoomShaper, was privately notified by mySites.guru on 27 July 2026 and released the fix on 12 August.

  • Unauthenticated PHP file inclusion leading to pre-authentication remote code execution: CVSS 4.0 9.3, Critical, tracked as CVE-2026-67285.
  • Unauthenticated arbitrary file write: CVSS 4.0 Medium, tracked as CVE-2026-67286.

mySites.guru said both flaws involve the Dynamic Content “load more” endpoint. The research was disclosed before publication, while exact requests and proof-of-concept details are being withheld. The advisory reports no public exploitation details.

Administrators should update to SP Page Builder 6.8.0 immediately. Sites that previously ran an affected release, including 6.7.1, should also be checked for signs of compromise.

Originally reported by mySites.guru.