SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-74254

CRITICAL · CVSS 9.3 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

The Page Builder CK Joomla extension is vulnerable to a critical SQL injection flaw in the styles model, affecting versions prior to 3.6.5. This vulnerability could allow attackers to execute arbitrary SQL commands, potentially compromising the integrity and confidentiality of the database. Joomla administrators and users of the affected extension should prioritize updating to version 3.6.5 or later to mitigate this risk.

CVE
CVE-2026-74254
Severity
CRITICAL
CVSS
9.3
EPSS
0.28%

Original NVD Description

Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in the backend.