Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote
CVE-2026-78375HighCVSS 8.6CVE published 14 September 2026Added to mySites.guru 14 September 2026

SP Page Builder (com_sppagebuilder) 6.8.0 to 6.9.0 - CVE-2026-78375 Author-level SQL Injection (full database read, CVSS 8.6), CVE-2026-79700 and CVE-2026-79701 Unauthenticated Captcha Bypass, plus three authorisation flaws - fixed in 6.9.1

Five security issues found by mySites.guru in SP Page Builder 6.9.0 and reported privately to JoomShaper on 8 September 2026, all fixed in 6.9.1 on 14 September 2026. The Joomla CNA published six CVE records on 14 September 2026 (the captcha bypass is split into one record per route), each naming Phil Taylor, mysites.guru as the finder. Scores and weakness classes below are the published ones. NOTE: JoomShaper's 6.9.1 changelog transposes CVE-2026-81565 and CVE-2026-81566 against the published records. The records are the authority: 81565 is the media upload, 81566 is the menu item. Do not re-map these two from the vendor changelog. 1. Author-level blind SQL injection, CVE-2026-78375 (CVSS 4.0 8.6 High, CWE-89, published affected range 5.2.1 to 6.9.0). The com_content integration plugin reads a value from the article-save request without an integer cast and concatenates it into a query. Any account that can save an article, an Author on a default Joomla site, can read the entire database one character at a time, including the Super User password hash. Requires the SP Page Builder content plugin to be enabled, which it is on any site using the builder inside articles. The record scores PR:H, which in Joomla CNA practice means above Registered rather than administrator. 2. Unauthenticated captcha bypass, CVE-2026-79700 and CVE-2026-79701 (both CVSS 4.0 6.9 Medium, CWE-807; published affected ranges Pro 5.1.4 to 6.9.0 and Pro 3.2.6 to 6.9.0). The contact form, opt-in form and form builder addons discard the real captcha result whenever the request claims the form is rendered inside a module, and the opt-in form additionally compared two attacker-supplied values. An anonymous visitor defeats reCAPTCHA on any of the three. These addons ship only in SP Page Builder Pro, so the free Lite edition is not affected by this one. 3. Editor-level media file rename escaping the media folders, CVE-2026-81564 (CVSS 4.0 7.0 High, CWE-22, published affected range 4.0.0 to 6.9.0). Renaming a chosen file to a path outside the web root can take the site down. 4. Author-level file write into the web root media tree, CVE-2026-81565 (CVSS 4.0 6.9 Medium, CWE-22, published affected range 4.0.0 to 6.9.0). The upload endpoint took its destination folder from the request without confining it. 5. Editor-level Joomla menu takeover, CVE-2026-81566 (CVSS 4.0 5.1 Medium, CWE-284, published affected range 4.0.0 to 6.9.0). The add-to-menu action called the menu-item model directly with no com_menus permission check, so an Editor could create or overwrite menu items including the site home item. Update to SP Page Builder 6.9.1 or later. Joomla 3 sites cannot install 6.9.1: JoomShaper published a separate Joomla 3 Security Patch. Its first release, 1.0.2, back-ported four of the five fixes but left the captcha bypass (CVE-2026-79701, which the Joomla CNA is extending to the Joomla 3 branch) live and shipped an incomplete fix for a reflected XSS in the dynamic content filter addon (CVE-2026-102426, Joomla 3 branch only, the 6.x branch was never affected). Version 1.0.3, released 30 September 2026, closes both. It installs only over SP Page Builder 5.6.1 and does not change the component version, so patched and unpatched Joomla 3 sites are indistinguishable by version and are deliberately not covered by this rule; the mySites.guru JoomShaper Joomla 3 patch tool detects and deploys it instead.

Is my site affected?

Affected
SP Page Builder from 6.8.0 up to but not including 6.9.1
Fixed in
6.9.1
What to do
Update SP Page Builder to 6.9.1 or later.

How CVE-2026-78375 is scored

The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.

8.6 High

CVSS 4.0, scored by Joomla CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

How it is reached

AV:N Attack vector
Network. Reachable across the internet
AC:L Attack complexity
Low. Nothing to work around, it just works
AT:N Attack requirements
None. Works against any affected install
PR:H Privileges required
High. Needs an account with elevated rights
UI:N User interaction
None. Nobody has to be tricked into anything

What it does to the site

VC:H Confidentiality
High. Everything the site holds can be read
VI:H Integrity
High. Data and files can be altered at will
VA:H Availability
High. The site can be taken down

What it does beyond the site

SC:N Confidentiality
None. Other systems keep their data
SI:N Integrity
None. Other systems keep their integrity
SA:N Availability
None. Other systems stay up

Timeline

  1. 14 September 2026CVE-2026-78375 record published by its CNA
  2. 14 September 2026mySites.guru check added for SP Page Builder (from 6.8.0 up to but not including 6.9.1)
  3. 14 September 2026We published: SQL Injection and a Captcha Bypass in the SP Page Builder Joomla Extension, found by mySites.guru

Rule details

Our disclosure post

Other vulnerabilities in SP Page Builder

Updating for CVE-2026-78375 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.

SP Page Builder

Latest safe version: 6.9.1

All 16 CVEs in SP Page Builder

References

CVE-2026-78375 questions

Which versions are affected by CVE-2026-78375?
CVE-2026-78375 affects SP Page Builder from 6.8.0 up to but not including 6.9.1. The fix is in 6.9.1.
How do I fix CVE-2026-78375?
Update SP Page Builder to 6.9.1 or later. Then confirm the installed version on the Joomla administrator's Extensions: Manage screen.
How severe is CVE-2026-78375?
Joomla CNA scores it 8.6 (High) under CVSS 4.0. In plain terms: reachable across the internet, needs an account with elevated rights and nobody has to be tricked into anything.

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

Rules current as of 5 October 2026.