Security Patch - Question | JoomShaper

Security Patch

CR

Chas Rowland

Extension 2 weeks ago

I get this message when I ty in stall J3 security

SP Page Builder security patch requires version 5.6.1 to be installed.

0
20 Answers
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 2 weeks ago #231696

Hi Chas,

Honest advice: If you have Joomla 3.10 and SPPB 3.8.10 keep this way by now. Only install firewall component that still can work inside J3.

And in the next few weeks, for your own (or client) safety, consider a Joomla 3-4-5 upgrade. You cannot keep J3 for so long. Joomla 3 is not supported by Joomla Team, there were many reasons of that.

0
CR
Chas Rowland
Accepted Answer
2 weeks ago #231698

I have Joomla 5.7.4

0
D
David Forés
Accepted Answer
2 weeks ago #231705

It seems you may have downloaded the wrong file.

Joomla 3 Security Patch for SP Page Builder (v1.0.1), as the name suggests, is for Joomla 3.

You'll likely need to download SP Page Builder 6 Pro or SP Page Builder 6 Lite in version v6.8.0.

0
CR
Chas Rowland
Accepted Answer
2 weeks ago #231712

Is the patch included with the latest pagebuilder because I have insalled that one

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 2 weeks ago #231723

Yes. But in your case use full & new versions (!) of everything.

0
F
Frits
Accepted Answer
2 weeks ago #231713

Hi,

About which J.3 security patch are we talking here?

We are running J.3.10.12 and SPPB 5.6.1, over the last weeks we installed several J.3 patches. Also we use mySites.Guru and they sent us an email today about a new found vulnerability.

Is there a new patch for J.3 covering this new vulnerability?

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 2 weeks ago #231722

Not yet for old J3 version. But I will ask for it.

0
F
Frits
Accepted Answer
2 weeks ago #231725

Would be very welcome.

We're working on replacing J.3 of course, but unfortunately this is not yet achieved.

0
F
Frits
Accepted Answer
4 days ago #232466

Hi Paul,

Any news on J.3 / is there a new patch (or is it maybe on its way)?

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 4 days ago #232468

@Frits

  1. What version of SPPB you have now?
  2. Do you have any firewall component installed. If yes, which one. If no, why not!
0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 2 weeks ago #231721

@Chas, so if you have new Joomla version, please install today's version of SPPB, not fix (!)

In general, in your case, always update site using full & new versions. Fix files are only for legacy users of old Joomla 3 etc.

0
CR
Chas Rowland
Accepted Answer
2 weeks ago #231727

Ok thanks

0
F
Frits
Accepted Answer
4 days ago #232485

Hi Paul,

1.We have SPPB 5.6.1.

2.We have Akeeba AdminTools for firewall.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 4 days ago #232486
  1. So delived by us patch should work: https://www.joomshaper.com/downloads/extension/sp-page-builder-joomla-3-security-patch

  2. I hope you have PRO, becuase only that can really protect site. Of course, I know that you have older version.

  3. I recommend installing also HTProtect (yes, works in J3)

0
F
Frits
Accepted Answer
4 days ago #232506

Hi Paul,

Thanks for your reply.

  1. I checked this patch; we already installed this version (1.0.1) some time ago. After that, on august 12, we got a message from mySites.Guru, see also https://mysites.guru/blog/sp-page-builder-pre-auth-rce-file-inclusion-disclosure/ As I understood it, a new vulnerability was found in SPBB, for which you released SPBB 6.8.0 (for Joomla installs that are up to date). This is why I wondered if, for J.3, also a new patch was needed. As I understand your reply, this is not the case?

  2. We do have Akeeba AdminTools Pro indeed.

  3. About HTProtect: I will definitely check it out. As you may have noticed we are using mySites.Guru, which also informs us about security issues

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 4 days ago #232525

ad 1) As I know not. The last updates were / and will be only for current SPPB 6.x. Legacy on long term is not good for anyone.

ad 2) Good.

ad 3) Yes, worth using it, also because they update extension very regularly and still works in J3 compare to new versions of Akeeba Tools etc.

0
F
Frits
Accepted Answer
3 days ago #232534

Ok, thanks again for your reply.

0
F
Frits
Accepted Answer
2 days ago #232635

Hi Paul,

Sorry to bother you again on this matter. As I said we are using mySites.guru by Phil Taylor for monitoring and updating our sites. The site that has SPPB on it is now marked in mySites with the information below. After reading this it seems to me that our version of SPPB (5.6.1) does need an upgrade - which we cannot do on J.3 - or patching, if that would be available.

Could you please let me know your reaction to this?

The message from mySites is:


This site has one or more vulnerable plugins installed

Critical Plugin: SP Page Builder (com_sppagebuilder) 4.0.0 to 6.6.1 - CVE-2026-48908 (CVSS 10.0) Unauthenticated Arbitrary File Upload (RCE)

Installed 5.6.1 → update to 6.6.2

SP Page Builder by JoomShaper, from 4.0.0 up to and including 6.6.1, exposes an asset.uploadCustomIcon task that accepts a file with no login and no file-type check. An unauthenticated remote attacker can upload a PHP web shell to a web-served folder and execute it, giving full remote code execution (CWE-284 Improper Access Control, CVSS v4.0 10.0). This was a zero-day found being actively exploited in the wild; observed droppers read configuration.php for database credentials and insert a rogue admin user for persistence. JoomShaper shipped 6.6.2 on 14 June 2026, which gates the endpoint behind an authenticated session with component-manage permission and a valid anti-CSRF token. Update to 6.6.2 or later immediately and check the site for web shells and rogue users. The Joomla 3 branch of SP Page Builder (3.8.x and earlier) is NOT affected by this particular flaw: the controllers/asset.php file that carries the uploadCustomIcon task does not exist in that branch at all, which is why this rule starts at 4.0.0. A Joomla 3 site on SP Page Builder 3.x is still exposed to the separate addon local-file-include issue in components/com_sppagebuilder/controller.php, and that one is closed by the Unpatched JoomShaper Security Holes tool.


0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 2 days ago #232638

If you have Joomla 3 you cannot update component to last version (6.8). We published update for J3 and SPPB users, https://www.joomshaper.com/downloads/extension/sp-page-builder-joomla-3-security-patch (use it, if you didn't so far)

For sure, you can (and should) install firewall component, and prey! The rest info you already got.


Talk with site owner about Joomla upgrade, otherwise near future can be dark, like in Gotham City.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 2 days ago #232639

Extra News!

Today we published Helix Ultimate security update for Joomla 4/5/6 (Download section), and extra version for Joomla 3 users only >> https://github.com/JoomShaper/helix-ultimate/releases/tag/j3-security-v1.0.2

0