Description
Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in the backend.
Published: 2026-08-17
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Page Builder CK extension for Joomla includes an unsanitized input vulnerability in its styles model that enables a SQL injection attack. An attacker who can supply crafted input to the affected parameter could read, modify, or delete database contents, potentially compromising site data integrity, confidentiality, and availability. This flaw maps to CWE-89.

Affected Systems

The vendor joomlack.fr offers the Page Builder CK extension for Joomla. Versions earlier than 3.6.5 are vulnerable; the front‑end component is fixed in 3.6.4, while the back‑end is fixed in 3.6.5. All earlier releases remain at risk.

Risk and Exploitability

The CVSS score of 9.3 classifies this flaw as critical, and while the EPSS score is not published, the lack of a KEV listing does not diminish the need for urgent action. The likely attack vector is through user-supplied input to the styles model on either the front‑end or back‑end, which an attacker could exploit without authentication or with minimal privileges. Once exploited, an attacker can gain full database control, facilitating data theft, site defacement, or further lateral movement.

Generated by OpenCVE AI on August 17, 2026 at 18:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Page Builder CK extension to version 3.6.5 on the back‑end and 3.6.4 or later on the front‑end as soon as possible.
  • If an upgrade is delayed, temporarily disable the Page Builder CK extension to block the exploitation pathway.
  • Deploy or update web application firewall rules to detect and block suspicious SQL injection patterns targeting the styles model.

Generated by OpenCVE AI on August 17, 2026 at 18:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.joomlack.fr/ cve-icon cve-icon
History

Mon, 17 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in the backend.
Title Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-17T17:34:30.810Z

Reserved: 2026-08-15T04:38:57.663Z

Link: CVE-2026-74254

cve-icon Vulnrichment

Updated: 2026-08-17T17:34:28.119Z

cve-icon NVD

Status : Received

Published: 2026-08-17T18:18:14.903

Modified: 2026-08-17T18:18:14.903

Link: CVE-2026-74254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T18:30:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')