SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-60030

HIGH · CVSS 8.7 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The Quix Page Builder Pro Joomla extension prior to version 6.2.1 is susceptible to broken access control, allowing authenticated users to upload media files without proper permission checks. This vulnerability could lead to unauthorized file uploads, potentially compromising the integrity of the media management system. Joomla administrators and users of the Quix Page Builder should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-60030
Severity
HIGH
CVSS
8.7
EPSS
0.24%

Original NVD Description

Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management permissions.