Executive brief
Page Builder CK is a popular Joomla extension that allows users to create website pages using a drag-and-drop interface. A SQL injection vulnerability in the styles model allows attackers to execute arbitrary database queries, potentially exposing sensitive website data or modifying content. Versions 3.6.4 and earlier contain this vulnerability in both frontend and backend components.
Technical details
The vulnerability is a SQL injection issue in the styles model of the Page Builder CK extension. It allows attackers to inject malicious SQL commands through user-controllable input, bypassing input validation and escaping mechanisms. The attack vector depends on network reachability to the Joomla installation and does not require prior authentication in some contexts. An attacker can extract database contents, modify or delete data, and potentially escalate privileges. Version 3.6.4 fixed the vector in the frontend, and version 3.6.5 addressed the backend variant.
Affected products
- JoomlaCK Page Builder CK < 3.6.5
Timeline
- 2026-08-17: disclosed