JoomlaForever.com!
  • Home
  • About US
  • News
  • Test & Reviews
  • Tutorials
  • Tips & Tricks
  • Contact US
  • Login

News - Security News

Update SP Page Builder to 6.9.1 for Six Security Fixes

Details
Written by: Bjørn Ove Bremnes
Parent Category: News
Category: News - Security News
Published: 16 September 2026

SP Page Builder 6.9.1 addresses six Joomla extension vulnerabilities affecting Free and Pro installations, including an authenticated blind SQL injection, unauthenticated CAPTCHA bypasses in Pro form addons, and media and menu access-control flaws. Site owners running version 6.9.0 or earlier should plan an update promptly, while administrators of older branches should confirm that earlier security releases have also been applied.

Read more: Update SP Page Builder to 6.9.1 for Six Security Fixes

Joomla Extension Vulnerabilities in SP Property Finder: Update to 4.1.4

Details
Written by: Bjørn Ove Bremnes
Parent Category: News
Category: News - Security News
Published: 16 September 2026

Two unauthenticated vulnerabilities in SP Property Finder affect versions 1.0.0 through 4.1.3: a Critical SQL injection issue and a mail relay–style form abuse issue. Joomla administrators should update to version 4.1.4 or later, then review database, administrator, and mail activity for signs of prior misuse.

Read more: Joomla Extension Vulnerabilities in SP Property Finder: Update to 4.1.4

HTProtect: An Independent Look at a Security-Focused Joomla Fleet Dashboard

Details
Written by: Bjørn Ove Bremnes
Parent Category: News
Category: News - Security News
Published: 27 August 2026

HTProtect is presented as a security-focused Joomla extension or service for organisations managing multiple Joomla sites. This independent overview considers where a central dashboard may improve operational visibility, what administrators should validate before deployment, and why it must complement—not replace—routine patching and established Joomla security controls.

Read more: HTProtect: An Independent Look at a Security-Focused Joomla Fleet Dashboard

Critical miniOrange OAuth Client Flaw: Update to 3.2.0 or Disable

Details
Written by: Bjørn Ove Bremnes
Parent Category: News
Category: News - Security News
Published: 27 August 2026

A critical Joomla extension vulnerability, CVE-2026-77995, affects miniOrange OAuth Client versions 1.0.0 through 3.1.9. Administrators should update to version 3.2.0 or later without delay, or disable the extension until they can do so.

Read more: Critical miniOrange OAuth Client Flaw: Update to 3.2.0 or Disable

Page 1 of 7

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7

About us

JF Logo

JoomlaForever.com is an independent source publishing news and tests about Joomla CMS.

Contact info

  • JoomlaForever.com!
  • Contact owner:  Bjørn Ove Bremnes
  • General info:
Social Medial:
  • JoomlaForever on Facebook
  • JoomlaForever on Twitter / X

Useful links

  • Home
  • About JoomlaForever.com
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
  • Comments Policy
  • Sitemap
  • Register account
  • Login
This site is sponsored by:
Bredc.com logo

All our content is original, and therefore it's copyrighted by JoomlaForever.com!

If you wish to use our content on another site, you will need explicit allowance from JoomlaForever.com! You can do this by emailing  or by using our form (see "Useful links")!

ALL RIGHTS © 2019 - 2026.
JoomlaForever.com!, and this site is not affiliated with or endorsed by The Joomla! Project™. Any products and services provided through this site are not supported or warrantied by The Joomla! Project or Open Source Matters, Inc. Use of the Joomla!® name, symbol, logo and related trademarks is permitted under a limited license granted by Open Source Matters, Inc...