Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index
CVE-2026-81566HighPublished 14 September 2026

SP Page Builder (com_sppagebuilder) 6.8.0 to 6.9.0 - CVE-2026-78375 Author-level SQL Injection (full database read, CVSS 7.1), CVE-2026-79700 and CVE-2026-79701 Unauthenticated Captcha Bypass, plus three authorisation flaws - fixed in 6.9.1

Five security issues found by mySites.guru in SP Page Builder 6.9.0 and reported privately to JoomShaper on 8 September 2026, all fixed in 6.9.1 on 14 September 2026. No CVE identifiers have been assigned to this round. 1. Author-level blind SQL injection (CVSS 4.0 7.1 High, CWE-89). The com_content integration plugin reads a value from the article-save request without an integer cast and concatenates it into a query. Any account that can save an article, an Author on a default Joomla site, can read the entire database one character at a time, including the Super User password hash. Requires the SP Page Builder content plugin to be enabled, which it is on any site using the builder inside articles. 2. Unauthenticated captcha bypass (CVSS 4.0 6.9 Medium, CWE-287/CWE-804). The contact form, opt-in form and form builder addons discard the real captcha result whenever the request claims the form is rendered inside a module, and the opt-in form additionally compared two attacker-supplied values. An anonymous visitor defeats reCAPTCHA on any of the three. These addons ship only in SP Page Builder Pro, so the free Lite edition is not affected by this one. 3. Editor-level media file rename escaping the media folders (CVSS 4.0 7.2 High, CWE-22). Renaming a chosen file to a path outside the web root can take the site down. 4. Editor-level Joomla menu takeover (CVSS 4.0 7.1 High, CWE-862). The add-to-menu action called the menu-item model directly with no com_menus permission check, so an Editor could create or overwrite menu items including the site home item. 5. Author-level file write into the web root media tree (CVSS 4.0 5.3 Medium, CWE-862). The upload endpoint took its destination folder from the request without confining it. Update to SP Page Builder 6.9.1 or later. Joomla 3 sites cannot install 6.9.1: JoomShaper published a separate Joomla 3 Security Patch 1.0.2 which back-ports four of the five fixes, but it installs only over SP Page Builder 5.6.1 and does not change the component version, so patched and unpatched Joomla 3 sites are indistinguishable by version and are deliberately not covered by this rule.

Affected versions: ≥ 6.8.0 and < 6.9.1

Official record: cve.org · NVD

Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.

Affected extensions and versions

Our disclosure post

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 14 September 2026.