Description
Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection.
Published: 2026-07-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Joomla extension Quix Page Builder Pro (v <6.2.1) is vulnerable to unauthenticated SQL injection, enabling an attacker to inject arbitrary SQL statements. This flaw, identified as CWE-89, can let an adversary read, modify, or delete data stored in the site’s database, compromising confidentiality and integrity of the Joomla installation. Based on the description, it is inferred that the injection can be triggered via specially crafted HTTP requests to the extension’s input handling routines.

Affected Systems

The flaw resides in the Quix Page Builder Pro extension distributed by themexpert.com for Joomla, affecting all releases prior to version 6.2.1. Sites running any earlier version are exposed unless a later update is applied.

Risk and Exploitability

With a CVSS score of 8.7, the flaw is classified as high severity. The EPSS score of less than 1% indicates that exploitation is currently rare, although the unauthenticated nature of the attack and its impact on data confidentiality and integrity make it a priority for remediation. The vulnerability is not listed in CISA’s KEV catalog, but an attacker could exploit it from any location with network reach to the site, without needing user accounts. If the database user has elevated privileges, the injected SQL could also be leveraged to further compromise the host.

Generated by OpenCVE AI on August 3, 2026 at 02:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Quix Page Builder Pro to version 6.2.1 or later, ensuring the latest security fixes are applied.
  • Remove any outdated or unpatched copies of the extension to eliminate the attack surface.
  • Configure Joomla’s role and permission system to restrict access to extension functionalities, and consider implementing a Web Application Firewall to block malformed SQL payloads.

Generated by OpenCVE AI on August 3, 2026 at 02:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Themexpert.com
Themexpert.com quix Page Builder Pro Extension For Joomla
Vendors & Products Themexpert.com
Themexpert.com quix Page Builder Pro Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection. Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection.

Thu, 16 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection.
Title Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Themexpert.com Quix Page Builder Pro Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T14:54:58.873Z

Reserved: 2026-06-28T18:39:37.301Z

Link: CVE-2026-58078

cve-icon Vulnrichment

Updated: 2026-07-16T12:32:15.500Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:00:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')