All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-74254
CRITICALpublished 2026-08-17 18:18 UTC · 15 hours ago · modified 2026-08-18 04:16 UTC
9.3
CVSS / 10
// description
Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in the backend.
// weaknesses (CWE)
- CWE-89