Executive brief
Quix Page Builder Pro is a popular drag-and-drop design tool used to create websites on the Joomla platform. A security vulnerability in this extension allows users with 'builder' permissions to inject malicious scripts into web pages. These scripts automatically execute when any other user, including site administrators, views the affected page, potentially leading to full site takeover or unauthorized data access.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the Quix Page Builder Pro extension for Joomla (versions 1.0 through 6.2.0). The flaw stems from the application's failure to sanitize SVG uploads and a lack of output escaping when rendering content. An authenticated attacker with 'builder' level privileges can inject malicious JavaScript into a page. This script is then executed in the context of any user who visits the page, including administrators. Given the high privileges of an administrator, this can lead to session hijacking or complete administrative compromise. The vulnerability is tracked as CVE-2026-60028.
Affected products
- themexpert.com Quix Page Builder Pro extension for Joomla 1.0-6.2.0
Timeline
- 2026-07-20: disclosed: CVE published to NVD dataset