Impact
The vulnerability is a reflected cross‑site scripting flaw in the Joomla Page Builder CK extension that is exploited via the iscontenttype URL parameter. An attacker who can influence that parameter can inject malicious JavaScript that executes in the context of any user who views the crafted page. This can lead to theft of session cookies, defacement, or delivery of malware, meeting the criteria for client‑side code execution (CWE‑79).
Affected Systems
All installations of the Page Builder CK extension from joomlack.fr that run a version older than 3.6.5 are affected. Joomla site owners who have not upgraded to the patched release should consider their site vulnerable to reflected XSS attacks originating from the iscontenttype parameter.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate level of severity. No EPSS score is reported, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that exploitation is possible but not currently widespread or actively used. The attack vector is via a web request, so any publicly accessible Joomla site using the vulnerable extension could be targeted by an attacker who can control the iscontenttype parameter in a URL or form. Because of the moderate score and lack of exploitation evidence, the risk is considered moderate but still significant for sites that accept unauthenticated or arbitrary parameters.
OpenCVE Enrichment