SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-60027

HIGH · CVSS 8.7 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The Quix Page Builder Pro extension for Joomla is susceptible to unauthenticated path traversal vulnerabilities, allowing attackers to read arbitrary files on the server through form elements. This issue arises when a published page contains a form, enabling unauthorized users to exploit the flaw. Joomla administrators and web developers using this extension should prioritize remediation to prevent potential data exposure and unauthorized access.

CVE
CVE-2026-60027
Severity
HIGH
CVSS
8.7
EPSS
0.35%

Original NVD Description

Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticated users frontend users are allowed traversal paths and read arbitrary files. Requires a published page with a Form element.