CVE-2026-77993
- EPSS 0.26%
- Veröffentlicht 24.08.2026 08:16:33
- Zuletzt bearbeitet 24.08.2026 08:16:33
Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected XSS via the iscontenttype parameter.
CVE-2026-77994
- EPSS 0.23%
- Veröffentlicht 24.08.2026 08:16:33
- Zuletzt bearbeitet 24.08.2026 08:16:33
Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the loadStyles method of the frontend page model.
CVE-2026-74254
- EPSS 0.28%
- Veröffentlicht 17.08.2026 17:10:04
- Zuletzt bearbeitet 18.08.2026 04:16:46
Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in the backend.
CVE-2026-63048
- EPSS 0.23%
- Veröffentlicht 22.07.2026 07:15:25
- Zuletzt bearbeitet 23.07.2026 16:17:47
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.
CVE-2026-62414
- EPSS 0.23%
- Veröffentlicht 20.07.2026 18:34:39
- Zuletzt bearbeitet 23.07.2026 16:17:46
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.