Skip to main content
mySites.guru
5+ live

Joomla extension security alerts (22 Aug) Fabrik 4.7.2ZOO: unauth RCEPhoca Cart: unauth SQLiJCE 2.9.99.10SP Page Builder RCE

CVE-2026-65877CriticalPublished 27 July 2026

SP Page Builder (com_sppagebuilder) 6.0.0 to 6.7.0 - CVE-2026-65766, CVE-2026-65876, CVE-2026-65877, CVE-2026-65878, CVE-2026-65879 - Unauthenticated SQL Injection (CVSS 9.2) and Open Mail Relay

Four vulnerabilities found by mySites.guru in SP Page Builder Pro 6.7.0 and reported privately to JoomShaper on 21 July 2026, fixed in 6.7.1 on 27 July 2026. The update applies to both the Pro and free editions. The Joomla CNA assigned four CVE IDs for these findings on 27 July 2026: CVE-2026-65766, CVE-2026-65877, CVE-2026-65878 and CVE-2026-65879. The records were still reserved rather than published at that point, so no per-finding mapping and no CNA scores are public yet. (1) Unauthenticated SQL injection (CWE-89, CVSS 4.0 8.7) in the Dynamic Content endpoint dynamic_content.getDynamicContentData: the sort direction was concatenated into the ORDER BY clause unchecked, and the endpoint was gated only by a CSRF token that Joomla issues to every anonymous visitor, so an anonymous attacker could read the entire database including password hashes. (2) Unauthenticated open mail relay (CWE-798) in the ajax_contact and form_builder addons: a single hardcoded salt shipped identically in every copy of the extension, so the signed recipient and sender could be forged offline, turning any site with a published contact form into a spam and phishing relay sending from its own domain and mail server. (3) Authenticated SQL injection in the media manager JSON view, reachable by a low-privilege author. (4) Authenticated arbitrary file delete via path traversal in the media delete action, needing only the create permission, allowing deletion of configuration.php or a protective .htaccess. Update to SP Page Builder 6.7.1 or later. There is no partial mitigation for the pre-authentication SQL injection other than updating. If a vulnerable version was internet-facing, treat the database as potentially read: rotate the Joomla secret and any stored API keys, and assume password hashes are known. Separate from CVE-2026-48908, the June 2026 unauthenticated icon-upload RCE fixed in 6.6.2. UPDATE 28 July 2026: the Joomla CNA published a fifth record for this release, CVE-2026-65876 (CVSS 4.0 9.2 CRITICAL, AV:N/AC:L/PR:N/UI:N) - an unauthenticated SQL injection caused by improper validation of the catid parameter in the loadMoreArticles endpoint, affecting all versions below 6.7.1. It is already covered by this rule; no version-boundary change was needed. Also within this rule: CVE-2026-66494 (unauthenticated stored XSS in the Shapes API endpoint, affecting 1.0.0 to 6.6.2), which sits below 6.7.1 and needs no separate row.

Affected versions: ≥ 6.0.0 and < 6.7.1

Official record: cve.org · NVD

Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.

Affected extensions and versions

Our disclosure post

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 25 August 2026.