Description
Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for public users.
Published: 2026-07-20
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Authenticated users with builder privileges can exploit the Quix Page Builder Pro extension for Joomla by inserting malicious script into id or class fields. These payloads are stored and rendered on public pages, causing script execution in visitors’ browsers. The issue arises from improper input validation in the extension’s page building interface and could lead to cross‑site scripting attacks that compromise user confidentiality and potentially allow credential theft or session hijacking.

Affected Systems

All Joomla sites that have installed the Quix Page Builder Pro extension with a version earlier than 6.2.1 are affected. The vulnerability is limited to the extension itself, not the core Joomla platform, and requires builder‑level access to create or edit pages.

Risk and Exploitability

Based on the description, the likely attack vector is internal to the CMS, as it requires authenticated builder user access. Once logged in, the attacker can persist malicious payloads in page content. With a CVSS score of 5.1, the vulnerability is of moderate severity, and an EPSS score of <1% indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, but because the malicious script runs in all site visitors’ browsers, the impact to users is significant.

Generated by OpenCVE AI on August 3, 2026 at 01:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Quix Page Builder Pro to version 6.2.1 or later, which fixes the stored XSS flaw.
  • If a rapid update is not possible, restrict or remove builder‑level privileges or disable the fields that allow script injection in page settings.
  • Implement a web application firewall rule or content‑security‑policy header to block external script executions on public pages.

Generated by OpenCVE AI on August 3, 2026 at 01:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Themexpert.com
Themexpert.com quix Page Builder Pro Extension For Joomla
Vendors & Products Themexpert.com
Themexpert.com quix Page Builder Pro Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for public users. Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for public users.

Tue, 21 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for public users.
Title Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Themexpert.com Quix Page Builder Pro Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T14:58:21.542Z

Reserved: 2026-07-08T05:31:35.889Z

Link: CVE-2026-60029

cve-icon Vulnrichment

Updated: 2026-07-21T16:27:50.570Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T01:30:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')