CVE-2026-74254

9.3

joomlack.fr · Page Builder CK extension for Joomla

The joomlack.fr Page Builder CK extension for Joomla versions prior to 3.6.5 is vulnerable to SQL injection in the styles model, allowing unauthenticated attackers to compromise database integrity.

Executive summary

An unauthenticated SQL injection vulnerability in the Page Builder CK extension for Joomla enables attackers to compromise database information and potentially gain unauthorized access.

Vulnerability

This is a SQL injection vulnerability (CWE-89) within the styles model of the extension. Unauthenticated attackers can inject malicious SQL commands to interact with the database, potentially leading to data extraction or modification.

Business impact

Successful exploitation of this SQL injection vulnerability could lead to the exposure of sensitive database contents, including user credentials or site configuration data. With a CVSS score of 9.3, this flaw poses a critical threat to the integrity of the Joomla installation and any associated business data stored within the database.

Remediation

Immediate Action: Update the Page Builder CK extension to version 3.6.5 or later to resolve the vulnerability in both the frontend and backend components.

Proactive Monitoring: Review database query logs for unusual patterns or signs of injection attempts, such as unexpected syntax errors or unauthorized data retrieval queries.

Compensating Controls: Utilize a Web Application Firewall (WAF) with SQL injection protection rules to filter malicious requests directed at the Joomla extension.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Administrators must update to version 3.6.5 immediately to secure the application. Failure to patch this extension leaves the database exposed to unauthorized access, which could result in a full site compromise if administrative or user accounts are stored within the affected database.

More joomlack.fr CVEs