SQL Injection Vulnerability in Joomla Extension Page Builder CK by joomlack.fr
CVE-2026-74254
9.3CRITICAL
What is CVE-2026-74254?
A SQL injection vulnerability exists in the Page Builder CK extension for Joomla, found in versions prior to 3.6.5. This issue arises specifically within the styles model and can potentially allow attackers to manipulate database queries. Version 3.6.4 addressed the frontend vector, while version 3.6.5 resolved the vulnerabilities in the backend. Users are advised to update to the latest version to mitigate the risk of exploitation.
Affected Version(s)
Page Builder CK extension for Joomla 1.0.0-3.6.4
