Junglewise Threat Intelligence

CVE-2026-58078: ThemeXpert Quix Page Builder Pro SQL injection in Joomla extension

CVE-2026-58078 · Severity: info · CVSS 8.7 · Published 2026-07-16

Executive brief

Quix Page Builder Pro, a popular drag-and-drop design tool for Joomla websites, contains a security vulnerability that allows unauthorized individuals to access the site's database. By sending a specially crafted request, an attacker can bypass security controls to view sensitive information, including user account details, password hashes, and private site configurations. This could lead to full site takeover, data theft, or exposure of customer information.

Technical details

An unauthenticated error-based SQL injection vulnerability exists in Quix Page Builder Pro versions 1.0 through 6.2.0. The flaw is located in a front-end AJAX endpoint used to load single Joomla articles. The endpoint fails to cast the 'article id' parameter to an integer before including it in a database existence check query. Because the application reflects database errors in its HTTP responses, an unauthenticated remote attacker can use crafted requests to extract data from any table in the Joomla database, including 'users' and 'configuration' tables. The vulnerability was fixed in version 6.2.1 by implementing proper input validation and type casting.

Affected products

  • themexpert.com Quix Page Builder Pro extension for Joomla 1.0-6.2.0

Timeline

  • 2026-07-16: disclosed: Vulnerability disclosed by mySites.guru and NVD record published.
  • 2026-07-16: patched: ThemeXpert released Quix 6.2.1 to address the issue.

References