Impact
The Joomla extension Quix Page Builder Pro contains a flaw that allows a user with builder-level privileges to store malicious script code within a page. The stored script is executed whenever any visitor or administrator views the page, enabling arbitrary client‑side code to run in the context of the user’s browser. The vulnerability stems from unescaped output and unsanitised SVG content, allowing the attacker to embed executable code.
Affected Systems
Any Joomla site using Quix Page Builder Pro version earlier than 6.2.1 is affected. The flaw can only be exploited by authenticated users who have builder privileges on the site. Sites that lack such users are not directly at risk.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. Because an attacker must be authenticated through a builder account, the immediate likelihood of public exploitation is limited, but the impact on compromised accounts is significant. The EPSS score of < 1% reflects a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. The attack vector is internal, requiring legitimate credentials, and the exploitation results in stored client‑side script that runs on every page view.
OpenCVE Enrichment