CyberICT

CVE-2026-56290

Joomlack · Published June 29, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Affected Products

  • Page Builder CK < 3.6.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H