PT-2026-61677 · Joomla · Quix Page Builder Pro

CVE-2026-60030

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Quix Page Builder versions prior to 6.2.1
Description The Joomla extension Quix Page Builder Pro contains an improper access control flaw. This issue allows authenticated users to upload media files, bypassing the restrictions normally imposed by their media management permissions.
Recommendations Update to version 6.2.1 or later.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-60030

Affected Products

Quix Page Builder Pro