Executive brief
Page Builder CK is a popular drag-and-drop page creation tool for the Joomla content management system. A security vulnerability in this extension allows logged-in users to upload malicious files to the server. This could allow an attacker to take full control of the website, leading to data theft, site defacement, or complete service disruption.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in the Page Builder CK extension for Joomla. The flaw allows an authenticated user with low-level privileges to upload dangerous file types, such as PHP scripts, to the web server. Because these files can be executed by the server, an attacker can achieve remote code execution (RCE), effectively gaining full system access within the context of the web server. The vulnerability affects versions 1.0.0 through 3.6.2.
Affected products
- joomlack.fr Page Builder CK extension for Joomla 1.0.0-3.6.2
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory