CVE-2026-77994

9.3

joomlack.fr · Page Builder CK extension for Joomla

The Page Builder CK extension for Joomla contains a second order SQL injection vulnerability in the loadStyles method of the frontend page model.

Executive summary

The Page Builder CK extension for Joomla is affected by a critical SQL injection vulnerability that allows unauthenticated attackers to compromise backend database integrity.

Vulnerability

This is a second order SQL injection vulnerability occurring within the loadStyles method of the frontend page model. The flaw is exploitable by unauthenticated remote attackers, as indicated by the CVSS vector AV:N/PR:N.

Business impact

Successful exploitation allows for unauthorized database manipulation, which can lead to full data exfiltration, modification of site content, or complete compromise of the Joomla environment. Given the high CVSS score of 9.3, this represents a critical risk to business continuity and data confidentiality.

Remediation

Immediate Action: Update the joomlack.fr Page Builder CK extension to version 3.6.5 or later immediately.

Proactive Monitoring: Monitor database query logs for anomalous patterns, specifically looking for unusual SQL syntax or unexpected execution times originating from the frontend page model.

Compensating Controls: Implement a Web Application Firewall (WAF) with updated rulesets designed to detect and block SQL injection patterns targeting Joomla extensions.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability carries a critical risk profile due to its potential for unauthenticated remote code execution or data theft. Organizations running affected versions of the Page Builder CK extension must prioritize patching to the latest version immediately to eliminate the injection vector.

More joomlack.fr CVEs