Security
SP Page Builder 6.7.1 fixes four Joomla vulnerabilities
JoomShaper has released SP Page Builder 6.7.1 to fix four vulnerabilities affecting version 6.7.0 and earlier, including a pre-authentication SQL injection and an unauthenticated mail relay.
mySites.guru reported the issues after auditing SP Page Builder, JoomShaper’s Joomla page-builder extension. The most serious flaw is a high-severity pre-authentication SQL injection rated CVSS 8.7, which could allow anonymous attackers to read database contents. A second issue is an unauthenticated mail relay rated medium severity at CVSS 6.9.
The remaining flaws require a low-privilege Joomla account: a high-severity SQL injection in the media manager (CVSS 7.1) and arbitrary file deletion (CVSS 7.2). The latter could allow an author-level user to remove files such as configuration.php or .htaccess.
The Joomla CNA assigned CVE-2026-65766, CVE-2026-65877, CVE-2026-65878 and CVE-2026-65879. mySites.guru says the issues were privately reported and does not report exploitation of these flaws in the wild.
Administrators should back up their sites and update SP Page Builder to 6.7.1 or later through Joomla’s extension update tools. Sites previously running an affected version should also review credentials and stored secrets because the SQL injection could expose database data.
Originally reported by mySites.guru.