Reflected XSS Vulnerability in Joomla Extension Page Builder CK by joomlack.fr
CVE-2026-77993

5.3MEDIUM

Key Information:

Vendor
CVE Published:
24 August 2026

What is CVE-2026-77993?

The Page Builder CK extension for Joomla is susceptible to a reflected Cross-Site Scripting (XSS) vulnerability when processing the iscontenttype parameter. This flaw could allow attackers to inject malicious scripts into web pages, potentially compromising user data and leading to unauthorized actions. Users of versions prior to 3.6.5 are particularly at risk and should consider immediate updates to safeguard their applications.

Affected Version(s)

Page Builder CK extension for Joomla 1.0.0-3.6.4

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ala Arfaoui
.