CVE-2026-56290
The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red
- EPSS probability
- 30.38%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-284, CWE-434
- Published
- 2026-06-29
- Last modified
- 2026-08-12
Affected products
- joomlack.fr JoomlaCK.fr Page Builder CK extension for Joomla