I get this message when I ty in stall J3 security
SP Page Builder security patch requires version 5.6.1 to be installed.
I get this message when I ty in stall J3 security
SP Page Builder security patch requires version 5.6.1 to be installed.
Hi Chas,
Honest advice: If you have Joomla 3.10 and SPPB 3.8.10 keep this way by now. Only install firewall component that still can work inside J3.
And in the next few weeks, for your own (or client) safety, consider a Joomla 3-4-5 upgrade. You cannot keep J3 for so long. Joomla 3 is not supported by Joomla Team, there were many reasons of that.
I have Joomla 5.7.4
It seems you may have downloaded the wrong file.
Joomla 3 Security Patch for SP Page Builder (v1.0.1), as the name suggests, is for Joomla 3.
You'll likely need to download SP Page Builder 6 Pro or SP Page Builder 6 Lite in version v6.8.0.
Is the patch included with the latest pagebuilder because I have insalled that one
Yes. But in your case use full & new versions (!) of everything.
Hi,
About which J.3 security patch are we talking here?
We are running J.3.10.12 and SPPB 5.6.1, over the last weeks we installed several J.3 patches. Also we use mySites.Guru and they sent us an email today about a new found vulnerability.
Is there a new patch for J.3 covering this new vulnerability?
Not yet for old J3 version. But I will ask for it.
Would be very welcome.
We're working on replacing J.3 of course, but unfortunately this is not yet achieved.
Hi Paul,
Any news on J.3 / is there a new patch (or is it maybe on its way)?
@Frits
@Chas, so if you have new Joomla version, please install today's version of SPPB, not fix (!)
In general, in your case, always update site using full & new versions. Fix files are only for legacy users of old Joomla 3 etc.
Ok thanks
Hi Paul,
1.We have SPPB 5.6.1.
2.We have Akeeba AdminTools for firewall.
So delived by us patch should work: https://www.joomshaper.com/downloads/extension/sp-page-builder-joomla-3-security-patch
I hope you have PRO, becuase only that can really protect site. Of course, I know that you have older version.
I recommend installing also HTProtect (yes, works in J3)
Hi Paul,
Thanks for your reply.
I checked this patch; we already installed this version (1.0.1) some time ago. After that, on august 12, we got a message from mySites.Guru, see also https://mysites.guru/blog/sp-page-builder-pre-auth-rce-file-inclusion-disclosure/ As I understood it, a new vulnerability was found in SPBB, for which you released SPBB 6.8.0 (for Joomla installs that are up to date). This is why I wondered if, for J.3, also a new patch was needed. As I understand your reply, this is not the case?
We do have Akeeba AdminTools Pro indeed.
About HTProtect: I will definitely check it out. As you may have noticed we are using mySites.Guru, which also informs us about security issues
ad 1) As I know not. The last updates were / and will be only for current SPPB 6.x. Legacy on long term is not good for anyone.
ad 2) Good.
ad 3) Yes, worth using it, also because they update extension very regularly and still works in J3 compare to new versions of Akeeba Tools etc.
Ok, thanks again for your reply.
Hi Paul,
Sorry to bother you again on this matter. As I said we are using mySites.guru by Phil Taylor for monitoring and updating our sites. The site that has SPPB on it is now marked in mySites with the information below. After reading this it seems to me that our version of SPPB (5.6.1) does need an upgrade - which we cannot do on J.3 - or patching, if that would be available.
Could you please let me know your reaction to this?
The message from mySites is:
This site has one or more vulnerable plugins installed
Critical Plugin: SP Page Builder (com_sppagebuilder) 4.0.0 to 6.6.1 - CVE-2026-48908 (CVSS 10.0) Unauthenticated Arbitrary File Upload (RCE)
Installed 5.6.1 → update to 6.6.2
SP Page Builder by JoomShaper, from 4.0.0 up to and including 6.6.1, exposes an asset.uploadCustomIcon task that accepts a file with no login and no file-type check. An unauthenticated remote attacker can upload a PHP web shell to a web-served folder and execute it, giving full remote code execution (CWE-284 Improper Access Control, CVSS v4.0 10.0). This was a zero-day found being actively exploited in the wild; observed droppers read configuration.php for database credentials and insert a rogue admin user for persistence. JoomShaper shipped 6.6.2 on 14 June 2026, which gates the endpoint behind an authenticated session with component-manage permission and a valid anti-CSRF token. Update to 6.6.2 or later immediately and check the site for web shells and rogue users. The Joomla 3 branch of SP Page Builder (3.8.x and earlier) is NOT affected by this particular flaw: the controllers/asset.php file that carries the uploadCustomIcon task does not exist in that branch at all, which is why this rule starts at 4.0.0. A Joomla 3 site on SP Page Builder 3.x is still exposed to the separate addon local-file-include issue in components/com_sppagebuilder/controller.php, and that one is closed by the Unpatched JoomShaper Security Holes tool.
If you have Joomla 3 you cannot update component to last version (6.8). We published update for J3 and SPPB users, https://www.joomshaper.com/downloads/extension/sp-page-builder-joomla-3-security-patch (use it, if you didn't so far)
For sure, you can (and should) install firewall component, and prey! The rest info you already got.
Talk with site owner about Joomla upgrade, otherwise near future can be dark, like in Gotham City.
Extra News!
Today we published Helix Ultimate security update for Joomla 4/5/6 (Download section), and extra version for Joomla 3 users only >> https://github.com/JoomShaper/helix-ultimate/releases/tag/j3-security-v1.0.2