Skip to main content

SEBLOD and Joomla 3

Still shipping for Joomla 3

Told Joomla 3 sites in May 2023 to stay on SEBLOD 3, and has said nothing since. SEBLOD 3.30.0 shipped in July 2026 with security fixes, including the unauthenticated path traversal.

Joomla extensions covered: SEBLOD. SEBLOD website

What they said

  • “If you site runs on Joomla! 3 and you'd like to stay on Joomla! 3 you should remain on SEBLOD 3”

    Said 5 May 2023Read it on their siteChecked 2 Oct 2026

What they did

  1. SEBLOD 3.30.0 ships for the Joomla 3 line, fixing the unauthenticated path traversal file download among other security issues

    Source

Known Joomla 3 vulnerabilities

  • Unrated

    SEBLOD (com_cck) below 3.30.0 - Unauthenticated Path Traversal Arbitrary File Download (CVE-2026-66914, CVSS 9.2)

    Affected: < 3.30.0

    CVE-2026-66914

See which of your sites run SEBLOD

Connect one site and mySites.guru audits it free, with no card. You see the core vulnerabilities still open on it, the extensions with known holes, and a one-click fix for the core ones.

Keep your Joomla 3 sites patched while you plan the move

One free audit of one site, no card. It shows the core vulnerabilities still open and the extensions with known holes.

Audit a Joomla 3 site free