CRITICAL

CVE-2026-56290

Joomlack Page Builder Ck 2026-06-29 CVSS v3.1
CVSS
9.8
KEV

Description

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Summary dbcve.org

Unauthenticated arbitrary file upload vulnerability in Page Builder CK Joomla extension (versions < 3.6.0) allowing attackers to upload executable files directly to the web server, leading to complete remote code execution.

Mitigation

Upgrade Page Builder CK extension to version 3.6.0 or later. If immediate upgrade is not feasible, disable the extension or implement web server-level access controls to block unauthorized upload endpoints.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-434 Unrestricted File Upload

EPSS Score

30.87%
Probability of exploitation in next 30 days
98.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE