VYPR

Page Builder CK

by Joomla

CVEs (5)

  • CVE-2026-63048CriJul 22, 2026
    risk 0.61cvss epss 0.00

    Joomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.

  • CVE-2026-77994CriAug 24, 2026
    risk 0.60cvss epss 0.00

    Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the loadStyles method of the frontend page model.

  • CVE-2026-74254CriAug 17, 2026
    risk 0.60cvss epss 0.00

    Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in the backend.

  • CVE-2026-77993MedAug 24, 2026
    risk 0.34cvss epss 0.00

    Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected XSS via the iscontenttype parameter.

  • CVE-2026-56290CriKEVJun 29, 2026
    risk 0.22cvss 9.8epss 0.31

    Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

VYPR — Vulnerability Intelligence