CVE-2026-77994
9.3joomlack.fr · Page Builder CK extension for Joomla
The Page Builder CK extension for Joomla contains a second order SQL injection vulnerability in the loadStyles method of the frontend page model.
Executive summary
The Page Builder CK extension for Joomla is affected by a critical SQL injection vulnerability that allows unauthenticated attackers to compromise backend database integrity.
Vulnerability
This is a second order SQL injection vulnerability occurring within the loadStyles method of the frontend page model. The flaw is exploitable by unauthenticated remote attackers, as indicated by the CVSS vector AV:N/PR:N.
Business impact
Successful exploitation allows for unauthorized database manipulation, which can lead to full data exfiltration, modification of site content, or complete compromise of the Joomla environment. Given the high CVSS score of 9.3, this represents a critical risk to business continuity and data confidentiality.
Remediation
Immediate Action: Update the joomlack.fr Page Builder CK extension to version 3.6.5 or later immediately.
Proactive Monitoring: Monitor database query logs for anomalous patterns, specifically looking for unusual SQL syntax or unexpected execution times originating from the frontend page model.
Compensating Controls: Implement a Web Application Firewall (WAF) with updated rulesets designed to detect and block SQL injection patterns targeting Joomla extensions.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability carries a critical risk profile due to its potential for unauthenticated remote code execution or data theft. Organizations running affected versions of the Page Builder CK extension must prioritize patching to the latest version immediately to eliminate the injection vector.