SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-60028

HIGH · CVSS 8.6 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The Quix Page Builder Pro extension for Joomla is vulnerable to an authenticated stored XSS attack, allowing authenticated users to inject malicious scripts that execute for any visitor or admin accessing the affected page. This vulnerability arises from unescaped output and unsanitized SVG content. Joomla site administrators using this extension should prioritize remediation to prevent potential exploitation and safeguard user data.

CVE
CVE-2026-60028
Severity
HIGH
CVSS
8.6
EPSS
0.25%

Original NVD Description

Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin viewing the page. Unescaped output + unsanitised SVG.