Description
Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected XSS via the iscontenttype parameter.
Published: 2026-08-24
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected XSS enabling arbitrary code execution in the user's browser
Action: Patch
AI Analysis

Impact

The vulnerability is a reflected cross‑site scripting flaw in the Joomla Page Builder CK extension that is exploited via the iscontenttype URL parameter. An attacker who can influence that parameter can inject malicious JavaScript that executes in the context of any user who views the crafted page. This can lead to theft of session cookies, defacement, or delivery of malware, meeting the criteria for client‑side code execution (CWE‑79).

Affected Systems

All installations of the Page Builder CK extension from joomlack.fr that run a version older than 3.6.5 are affected. Joomla site owners who have not upgraded to the patched release should consider their site vulnerable to reflected XSS attacks originating from the iscontenttype parameter.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate level of severity. No EPSS score is reported, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that exploitation is possible but not currently widespread or actively used. The attack vector is via a web request, so any publicly accessible Joomla site using the vulnerable extension could be targeted by an attacker who can control the iscontenttype parameter in a URL or form. Because of the moderate score and lack of exploitation evidence, the risk is considered moderate but still significant for sites that accept unauthenticated or arbitrary parameters.

Generated by OpenCVE AI on August 24, 2026 at 09:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Page Builder CK extension to version 3.6.5 or newer
  • If an upgrade cannot be performed immediately, sanitize or escape the iscontenttype parameter to neutralize scripts
  • Apply output encoding to all dynamic content to defend against reflected XSS

Generated by OpenCVE AI on August 24, 2026 at 09:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.joomlack.fr/ cve-icon cve-icon
History

Tue, 25 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Joomlack
Joomlack page Builder Ck Extension For Joomla
Vendors & Products Joomlack
Joomlack page Builder Ck Extension For Joomla

Mon, 24 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected XSS via the iscontenttype parameter.
Title Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Joomlack Page Builder Ck Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-25T04:51:47.745Z

Reserved: 2026-08-21T19:05:09.013Z

Link: CVE-2026-77993

cve-icon Vulnrichment

Updated: 2026-08-24T16:29:22.080Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T08:16:33.677

Modified: 2026-08-26T16:35:20.160

Link: CVE-2026-77993

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')