Security
SP Page Builder flaws fixed in version 6.9.1
JoomShaper has fixed five security vulnerabilities in the Joomla SP Page Builder extension, including a High-severity SQL injection and a Medium-severity captcha bypass.
mySites.guru reported the issues in SP Page Builder 6.9.0 and says JoomShaper addressed them in version 6.9.1. The disclosure identifies the most serious flaw as an Author-level blind SQL injection in the article integration, tracked as CVE-2026-78375. It can allow an authenticated Author to extract database contents, including password hashes, through timing-based queries.
A separate issue, CVE-2026-79701, allows unauthenticated visitors to bypass captcha checks on the Contact, Opt-in and Form Builder addons. The affected addons are part of the Pro edition; the report says the free Lite edition is not affected by this flaw. The bypass could expose forms to spam, list poisoning and unwanted mail submissions.
- The SQL injection is rated High.
- The captcha bypass is rated Medium.
- Three additional access-controlled issues involved file renaming, Joomla menu changes and file writing outside intended media paths.
mySites.guru says it reported the findings privately and has not published the requests or proof-of-concept payloads. Administrators should update to 6.9.1 immediately. Joomla 3 sites that cannot install that release should apply the separate patch described in the advisory.
Originally reported by mySites.guru.