Authenticated File Upload Vulnerability in Page Builder CK Joomla Extension
CVE-2026-63048

9.4CRITICAL

Key Information:

Vendor
CVE Published:
22 July 2026

What is CVE-2026-63048?

The Joomla extension Page Builder CK is exposed to a vulnerability that allows authenticated users to upload arbitrary files. This can potentially lead to remote code execution on the affected server, compromising the integrity and security of web applications. Proper security measures and timely updates are recommended to mitigate risks associated with this vulnerability.

Affected Version(s)

Page Builder CK extension for Joomla 1.0.0-3.6.2

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor
.