Security Advisory

CVE-2026-56290

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-29 14:31:37
Last updated 2026-07-23 14:56:13
Assigner Joomla
CVSS score 10.0
State PUBLISHED

Description

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.