Fixed an authorized SQL injection vulnerability in article and module save operations caused by insufficient input validation of database identifiers. [CVE-2026-78375]
Fixed a CAPTCHA bypass vulnerability in the Opt-in Form addon by validating CAPTCHA parameters against the configured addon settings instead of request-supplied values. [CVE-2026-79700]
Fixed a CAPTCHA bypass vulnerability in the Contact Form, Opt-in Form and Form Builder addons when placed inside a module, ensuring the CAPTCHA plugin's verification result is always enforced. [CVE-2026-79701]
Fixed an authorization issue in the Media Manager that allowed users with editing permissions to rename files outside the intended media directories. [CVE-2026-81564]
Fixed a permission issue when creating or updating menu items through SP Page Builder, ensuring the required Joomla menu permissions are properly enforced. [CVE-2026-81565]
Fixed an issue in the Media Manager that allowed users with author-level permissions to upload files to unintended directories within the site. [CVE-2026-81566]