Second Order SQL Injection in Joomla Extension Page Builder CK by joomlack.fr
CVE-2026-77994
9.3CRITICAL
What is CVE-2026-77994?
The Page Builder CK extension for Joomla is susceptible to a second order SQL injection vulnerability. This security issue arises due to improper handling in the loadStyles method of the frontend page model, allowing attackers to manipulate database queries and potentially access sensitive information. Users are encouraged to update to the latest version to mitigate risks associated with this vulnerability.
Affected Version(s)
Page Builder CK extension for Joomla 1.0.0-3.6.4
