SEBLOD and Joomla 3
Told Joomla 3 sites in May 2023 to stay on SEBLOD 3, and has said nothing since. SEBLOD 3.30.0 shipped in July 2026 with security fixes, including the unauthenticated path traversal.
Joomla extensions covered: SEBLOD. SEBLOD website
What they said
“If you site runs on Joomla! 3 and you'd like to stay on Joomla! 3 you should remain on SEBLOD 3”
Said 5 May 2023Read it on their siteChecked 2 Oct 2026
What they did
SEBLOD 3.30.0 ships for the Joomla 3 line, fixing the unauthenticated path traversal file download among other security issues
Known Joomla 3 vulnerabilities
- Unrated
SEBLOD (com_cck) below 3.30.0 - Unauthenticated Path Traversal Arbitrary File Download (CVE-2026-66914, CVSS 9.2)
Affected: < 3.30.0
See which of your sites run SEBLOD
Connect one site and mySites.guru audits it free, with no card. You see the core vulnerabilities still open on it, the extensions with known holes, and a one-click fix for the core ones.
Keep your Joomla 3 sites patched while you plan the move
One free audit of one site, no card. It shows the core vulnerabilities still open and the extensions with known holes.