Executive brief
Quix Page Builder Pro, a popular drag-and-drop design tool for Joomla websites, contains a security flaw in its form elements. An unauthorized person can exploit this to access and read sensitive files on the web server that should normally be restricted. This could lead to the exposure of configuration files, system data, or other private information, potentially compromising the entire website's security.
Technical details
A path traversal vulnerability (CWE-22) exists in the Quix Page Builder Pro extension for Joomla (versions 1.0 through 6.2.0). The flaw is located within the handling of form elements on published pages. An unauthenticated remote attacker can use specially crafted requests to bypass directory restrictions and read arbitrary files from the underlying filesystem. The attack requires at least one published page containing a Form element to be accessible. The vulnerability has been assigned a CVSS 4.0 base score of 8.7, reflecting high confidentiality impact.
Affected products
- ThemeXpert Quix Page Builder Pro extension for Joomla 1.0-6.2.0
Timeline
- 2026-07-20: advisory: CVE published by Joomla! Project