CVE-2026-77994: Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5
Published Aug 24, 2026
·Updated
Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the loadStyles method of the frontend page model.
Affected Software
1 affected component
Joomla Page Builder CK<3.6.5
Event History
Aug 24, 2026
CVE Published
via MITRE·07:55 AM
Data Sourced
via MITRE·07:55 AM
DescriptionWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which component and code path are affected?
The affected component is the Page Builder CK extension for Joomla, specifically the loadStyles method in the frontend page model.
2
What versions are affected?
Page Builder CK versions earlier than 3.6.5 are affected.
3
What type of SQL injection is involved?
The issue is identified as a second-order SQL injection vulnerability.