CVE-2026-56290

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Scoring

Severity
CRITICAL
CVSS base score
10
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red
EPSS probability
30.38%
CISA KEV
Known exploited vulnerability
CWE
CWE-284, CWE-434
Published
2026-06-29
Last modified
2026-08-12

Affected products

Weakness type

Markdown version · Browse all CVEs