SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-60026

HIGH · CVSS 8.9 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The Quix Page Builder Pro extension for Joomla versions prior to 6.2.1 is vulnerable to authenticated PHP code execution, allowing users with builder permissions to inject PHP tags into element content. This vulnerability can lead to arbitrary code execution, particularly when caching is enabled, which is the default setting. Joomla administrators and developers using this extension should prioritize patching to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-60026
Severity
HIGH
CVSS
8.9
EPSS
0.31%

Original NVD Description

Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in element content, that got executed via view-cache include(). Requires caching on (default).