CVE-2026-74254: Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5
Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in the backend.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Joomla extension - Page Builder CK (joomlack.fr)to a version that resolves this vulnerability.Fixed in 3.6.5 - Upgrade
Upgrade
Joomla extension - Page Builder CK (joomlack.fr)to a version that resolves this vulnerability.Fixed in 3.6.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-74254?
CVE-2026-74254 has a risk score of 56.
How do I fix CVE-2026-74254?
To fix CVE-2026-74254, update the Joomla Page Builder CK to version 3.6.5 or later.
What type of vulnerability is CVE-2026-74254?
CVE-2026-74254 is an SQL injection vulnerability.
Which versions of Joomla Page Builder CK are affected by CVE-2026-74254?
Versions of Joomla Page Builder CK prior to 3.6.5 are affected by CVE-2026-74254.
What component of Joomla Page Builder CK does CVE-2026-74254 affect?
CVE-2026-74254 affects the styles model within the Page Builder CK extension.