Authenticated PHP Code Execution in Quix Page Builder Pro by ThemExpert
CVE-2026-60026
8.9HIGH
What is CVE-2026-60026?
The Quix Page Builder Pro extension for Joomla allows authenticated users with builder permissions to inject PHP tags into element content. This can lead to unauthorized PHP code execution through the application's view-cache functionality, which requires caching to be enabled for exploitation. This vulnerability could compromise the security of Joomla sites utilizing this extension, highlighting the need for immediate remediation.
Affected Version(s)
Quix Page Builder Pro extension for Joomla 1.0-6.2.0
