Fix Unauthenticated SQL Injection ?? - Forum | JoomShaper
Staff replied SP Page Builder

Fix Unauthenticated SQL Injection ??

Asked by ssnobben 1 month ago Last activity 1 month ago

When will you fix this security issue!???
Plugin: SP Page Builder (com_sppagebuilder) 6.7.1 to 6.7.x - Unauthenticated SQL Injection (actively exploited, incomplete 6.7.1 patch, no vendor fix released yet)

SP Page Builder 6.7.1 still contains an unauthenticated SQL injection in the front-end article loading endpoint. The 6.7.1 security release did not close it. The site controller task articles.loadMoreArticles reads its parameters straight out of the raw JSON request body (php://input) with no login, no permission check and no CSRF token of any kind. The catid value taken from that body is passed unfiltered into SppagebuilderHelperArticles::getCategories(), which interpolates the array directly into a SQL IN() clause with implode(). The ArrayHelper::toInteger() sanitisation added for the sibling query runs one line too late to protect that call. Any anonymous visitor can therefore read the entire site database, including user records and password hashes. Confirmed by reading the shipping com_sppagebuilder_pro 6.7.1 package on 10 August 2026. This is reported to be under active exploitation in the wild. JoomShaper has NOT released a patch. The vendor has published a 6.8.0 changelog entry stating "Fixed an unauthenticated SQL injection in the article loading endpoint" and says the release is due "in the next days or week". As of 10 August 2026 the latest available download is still 6.7.1, so there is currently no version you can update to. Temporary mitigation until 6.8.0 is published: edit components/com_sppagebuilder/controllers/articles.php and add die(); as the very first statement inside the loadMoreArticles() function. This blocks the attack. It also disables the endpoint, so the "Load more" button on article list addons will stop working until you remove the line. Update to 6.8.0 or later as soon as it is released, then remove the die(). This is separate from CVE-2026-65766 (the Dynamic Content ORDER BY injection), which was genuinely fixed in 6.7.1 and is covered by the 6.0.0 to 6.7.0 rule.

14 replies

Addington

We're having the same issues and questions, but wouldn't it be better if this post was private - it seems like it gives a lot of info to anyone with bad intentions.

Just a thought.

ssnobben Asked this

This is not new info and its a shame Joomshaper have no security audit of their software and have 100% attention to this matter.. So what to do??

Paul Frankowski Senior Staff
1 month ago · edited

A new fixed version is ready, I hope it will be published very soon. Believe me, I also asked for a speed-up.

@Addington, I fully agree, but what I can do (I asked many times), but people do what they want anyway.

It's like in the old joke: Look, everyone—my neighbor forgot to lock the door and windows, and he lives on the ground floor. After a second his wife says, “This is our apartment.”


Yesterday, and today, I shared fixed file here on forum, if somebody needs it, it's inside Hidden Content

Sandra97

Hi Paul,

How can I have the fixed file?

Thansk in advance

Martin

May I ask, too?

Ziaul Kabir Staff

Hi,

Thank you for bringing this to our attention. We’ve already reviewed our full codebase and identified the related issues. All necessary fixes have been implemented, and SP Page Builder 6.8.0 is currently in the testing stage.

We’re making sure that all identified issues are properly addressed and thoroughly tested before the release. We hope this will ensure everything works smoothly and that you won’t experience any further trouble after this update.

Thank you for your patience and understanding.

Best regards,

Paul Frankowski Senior Staff

Check your mailing box. But full update should be soon.

ssnobben Asked this

OK I checked my email but never got any "full update"

Addington

I haven't had an email either.
Are you still planning to release the new version 6.8.0 today? I see in another chat that you say your developers are in a different time zone - so maybe they are sleeping now? It makes no difference, but could you pick any time zone and say approximately which hour today you plan to make this release please?

Paul Frankowski Senior Staff

I send e-mail to @Sandra97 only.

Addington

Maybe if a minor bug fixes or some new features are holding up the release of 6.8.0, you could just ship version 6.7.2 with the security fix and take your time to get 6.8.0 perfect?

Honestly, as a website owner, for me its security first, bug fixes second, compatability with new releases of PHP and Joomla 3rd, but enhancements are a very distant 4th.

johnny

Any update on an official fix being released for this critical vulnerability? The communication around this has been extremely bad.

Log in to reply.