SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-60029

MEDIUM · CVSS 5.1 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The Quix Page Builder Pro extension for Joomla versions prior to 6.2.1 is susceptible to an authenticated stored cross-site scripting (XSS) vulnerability, allowing authenticated users to inject malicious scripts that could execute in the context of public users. This could lead to unauthorized actions or data exposure for users interacting with the affected pages. Joomla administrators and developers utilizing this extension should prioritize applying the latest updates to mitigate potential exploitation risks.

CVE
CVE-2026-60029
Severity
MEDIUM
CVSS
5.1
EPSS
0.25%

Original NVD Description

Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for public users.