Description
Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin viewing the page. Unescaped output + unsanitised SVG.
Published: 2026-07-20
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Joomla extension Quix Page Builder Pro contains a flaw that allows a user with builder-level privileges to store malicious script code within a page. The stored script is executed whenever any visitor or administrator views the page, enabling arbitrary client‑side code to run in the context of the user’s browser. The vulnerability stems from unescaped output and unsanitised SVG content, allowing the attacker to embed executable code.

Affected Systems

Any Joomla site using Quix Page Builder Pro version earlier than 6.2.1 is affected. The flaw can only be exploited by authenticated users who have builder privileges on the site. Sites that lack such users are not directly at risk.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. Because an attacker must be authenticated through a builder account, the immediate likelihood of public exploitation is limited, but the impact on compromised accounts is significant. The EPSS score of < 1% reflects a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. The attack vector is internal, requiring legitimate credentials, and the exploitation results in stored client‑side script that runs on every page view.

Generated by OpenCVE AI on August 4, 2026 at 06:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Quix Page Builder Pro extension to version 6.2.1 or later.
  • Restrict or remove builder‑level permissions from accounts until the patch is applied.
  • Implement server‑side sanitisation and output escaping to ensure SVG content is cleaned before rendering.

Generated by OpenCVE AI on August 4, 2026 at 06:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Themexpert.com
Themexpert.com quix Page Builder Pro Extension For Joomla
Vendors & Products Themexpert.com
Themexpert.com quix Page Builder Pro Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin viewing the page. Unescaped output + unsanitised SVG. Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin viewing the page. Unescaped output + unsanitised SVG.

Mon, 20 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin viewing the page. Unescaped output + unsanitised SVG.
Title Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Themexpert.com Quix Page Builder Pro Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T14:55:21.661Z

Reserved: 2026-07-08T05:31:35.889Z

Link: CVE-2026-60028

cve-icon Vulnrichment

Updated: 2026-07-20T20:12:24.496Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T06:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')