Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

SP Page Builder flaws fixed in version 6.9.1

JoomShaper has fixed five security vulnerabilities in the Joomla SP Page Builder extension, including a High-severity SQL injection and a Medium-severity captcha bypass.

mySites.guru reported the issues in SP Page Builder 6.9.0 and says JoomShaper addressed them in version 6.9.1. The disclosure identifies the most serious flaw as an Author-level blind SQL injection in the article integration, tracked as CVE-2026-78375. It can allow an authenticated Author to extract database contents, including password hashes, through timing-based queries.

A separate issue, CVE-2026-79701, allows unauthenticated visitors to bypass captcha checks on the Contact, Opt-in and Form Builder addons. The affected addons are part of the Pro edition; the report says the free Lite edition is not affected by this flaw. The bypass could expose forms to spam, list poisoning and unwanted mail submissions.

  • The SQL injection is rated High.
  • The captcha bypass is rated Medium.
  • Three additional access-controlled issues involved file renaming, Joomla menu changes and file writing outside intended media paths.

mySites.guru says it reported the findings privately and has not published the requests or proof-of-concept payloads. Administrators should update to 6.9.1 immediately. Joomla 3 sites that cannot install that release should apply the separate patch described in the advisory.

Originally reported by mySites.guru.