PT-2026-61674 · Joomla · Quix Page Builder Pro
CVE-2026-60027
·
Published
2026-07-20
·
Updated
2026-07-20
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Quix Page Builder Pro versions prior to 6.2.1
Description
An unauthenticated path traversal issue exists in the Quix Page Builder Pro Joomla extension. This flaw allows unauthenticated frontend users to use traversal paths to read arbitrary files on the server. The exploitation of this issue requires a published page that contains a Form element.
Recommendations
Update Quix Page Builder Pro to version 6.2.1 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quix Page Builder Pro