Description
Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in the backend.
Published: 2026-08-17
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Page Builder CK extension for Joomla includes an unsanitized input vulnerability in its styles model that enables a SQL injection attack. An attacker who can supply crafted input to the affected parameter could read, modify, or delete database contents, potentially compromising site data integrity, confidentiality, and availability. This flaw maps to CWE-89.

Affected Systems

The vendor joomlack.fr offers the Page Builder CK extension for Joomla. Versions earlier than 3.6.5 are vulnerable; the front‑end component is fixed in 3.6.4, while the back‑end is fixed in 3.6.5. All earlier releases remain at risk.

Risk and Exploitability

The CVSS score of 9.3 classifies this flaw as critical, and while the EPSS score is not published, the lack of a KEV listing does not diminish the need for urgent action. The likely attack vector is through user-supplied input to the styles model on either the front‑end or back‑end, which an attacker could exploit without authentication or with minimal privileges. Once exploited, an attacker can gain full database control, facilitating data theft, site defacement, or further lateral movement.

Generated by OpenCVE AI on August 17, 2026 at 18:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Page Builder CK extension to version 3.6.5 on the back‑end and 3.6.4 or later on the front‑end as soon as possible.
  • If an upgrade is delayed, temporarily disable the Page Builder CK extension to block the exploitation pathway.
  • Deploy or update web application firewall rules to detect and block suspicious SQL injection patterns targeting the styles model.

Generated by OpenCVE AI on August 17, 2026 at 18:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.joomlack.fr/ cve-icon cve-icon
History

Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Joomlack
Joomlack page Builder Ck
Vendors & Products Joomlack
Joomlack page Builder Ck

Mon, 17 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in the backend.
Title Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Joomlack Page Builder Ck
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-24T07:54:30.814Z

Reserved: 2026-08-15T04:38:57.663Z

Link: CVE-2026-74254

cve-icon Vulnrichment

Updated: 2026-08-17T17:34:28.119Z

cve-icon NVD

Status : Deferred

Published: 2026-08-17T18:18:14.903

Modified: 2026-08-26T16:35:20.160

Link: CVE-2026-74254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:19:41Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')