Affected versions: ≥ 4.0.0 and < 6.6.2
Full advisory: our disclosure post
Joomla extension security alerts (22 Aug) Fabrik 4.7.2ZOO: unauth RCEPhoca Cart: unauth SQLiJCE 2.9.99.10SP Page Builder RCE
SP Page Builder by JoomShaper, from 4.0.0 up to and including 6.6.1, exposes an asset.uploadCustomIcon task that accepts a file with no login and no file-type check. An unauthenticated remote attacker can upload a PHP web shell to a web-served folder and execute it, giving full remote code execution (CWE-284 Improper Access Control, CVSS v4.0 10.0). This was a zero-day found being actively exploited in the wild; observed droppers read configuration.php for database credentials and insert a rogue admin user for persistence. JoomShaper shipped 6.6.2 on 14 June 2026, which gates the endpoint behind an authenticated session with component-manage permission and a valid anti-CSRF token. Update to 6.6.2 or later immediately and check the site for web shells and rogue users. The Joomla 3 branch of SP Page Builder (3.8.x and earlier) is NOT affected by this particular flaw: the controllers/asset.php file that carries the uploadCustomIcon task does not exist in that branch at all, which is why this rule starts at 4.0.0. A Joomla 3 site on SP Page Builder 3.x is still exposed to the separate addon local-file-include issue in components/com_sppagebuilder/controller.php, and that one is closed by the Unpatched JoomShaper Security Holes tool.
Affected versions: ≥ 4.0.0 and < 6.6.2
Official record: cve.org · NVD
Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.
Affected versions: ≥ 4.0.0 and < 6.6.2
Full advisory: our disclosure post
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
Rules current as of 25 August 2026.