CVE-2026-60026
Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in element content, that got executed via view-cache include(). Requires caching on (default).
| CWE | CWE-94 |
| Vendor | themexpert.com |
| Product | quix page builder pro extension for joomla |
| Published | Jul 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for themexpert.com quix page builder pro extension for joomla
Be the first to know when new unknown vulnerabilities affecting themexpert.com quix page builder pro extension for joomla are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
themexpert.com / Quix Page Builder Pro extension for Joomla
1.0-6.2.0