Critical severityNVD Advisory· Published Aug 17, 2026· Updated Aug 26, 2026
CVE-2026-74254
CVE-2026-74254
Description
Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in the backend.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.6.5
Patches
Vulnerability mechanics
References
1News mentions
2- Joomla: 17 Vulnerabilities Disclosed, Including Critical Code & SQL Injection FlawsVypr Intelligence · Aug 19, 2026
- Joomla Extensions: Two Critical SQLi and Two Medium Flaws Disclosed TogetherVypr Intelligence · Aug 17, 2026