Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote
CVE-2026-78374MediumCVSS 6.9Published 28 August 2026

T4 Page Builder (com_t4pagebuilder) below 2.3.0 - Unauthenticated Mail Relay and AcyMailing Table Writes, Missing CSRF Token

JoomlArt released T4 Page Builder 2.3.0 on 28 August 2026, fixing an unauthenticated open mail relay that mySites.guru reported to the vendor and to the Joomla Security Strike Team on 17 August 2026, after finding it in use on a client site. In versions below 2.3.0 the front-end contact action is exempt from the component's ACL checks and accepts a recipient address supplied in the request, so any anonymous visitor can send mail to arbitrary addresses using the site's configured sender identity: the site becomes an open mail relay for spam and phishing sent under its own domain, SPF and DKIM. The same endpoint requires no Joomla form token (CSRF), applies no rate limiting, and relies on whether a captcha plugin is enabled rather than validating a captcha response. The subscribe task on the same endpoint allows unauthenticated writes to connected AcyMailing subscription tables. The component also ships a live Mailchimp API key hardcoded into its source, which should be rotated by its owner. mySites.guru verified the fix by auditing the released 2.3.0 package on 3 September 2026: the contact action now requires a valid form token, rate limits per IP (5 requests per 10 minutes by default), validates captcha explicitly, and delivers only to administrator addresses via getAdminMails() rather than the request-supplied recipient. The hardcoded key is absent from the 2.3.0 package and the Mailchimp credentials are read from component parameters. Update to T4 Page Builder 2.3.0 or later from the JoomlArt member area, clear the Joomla cache, then re-test all contact and subscription forms. Temporary mitigation: unpublish public contact and subscription forms built with T4 Page Builder until the update is applied. CVE-2026-78374 was assigned by the Joomla CNA on 10 September 2026, at the reporter's request rather than the vendor's. The record is reserved and not yet published at MITRE or NVD, and JoomlArt still credits no reporter. The vendor states no affected floor, so every version below 2.3.0 is treated as affected.

Affected versions: < 2.3.0

Official record: cve.org · NVD

Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.

How CVE-2026-78374 is scored

The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.

6.9 Medium

CVSS 4.0, scored by Joomla CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N

How it is reached

AV:N Attack vector
Network. Reachable across the internet
AC:L Attack complexity
Low. Nothing to work around, it just works
AT:N Attack requirements
None. Works against any affected install
PR:N Privileges required
None. No account needed
UI:N User interaction
None. Nobody has to be tricked into anything

What it does to the site

VC:L Confidentiality
Low. Some data can be read
VI:N Integrity
None. Nothing can be altered
VA:L Availability
Low. The site slows or stutters

What it does beyond the site

SC:N Confidentiality
None. Other systems keep their data
SI:N Integrity
None. Other systems keep their integrity
SA:N Availability
None. Other systems stay up

mySites.guru rates this High. Where our assessment and the published record differ, your sites are checked against ours.

Affected extensions and versions

Our disclosure post

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 2 October 2026.