CVE-2026-74254: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in joomlack.fr Page Builder CK extension for Joomla
The Joomla extension Page Builder CK versions up to 3.6.4 are vulnerable to an SQL injection flaw affecting the styles model. This vulnerability allows an attacker to execute arbitrary SQL commands due to improper neutralization of special elements in SQL queries. The issue was fixed in version 3.6.5 for the backend and in 3.6.4 for the frontend.
AI Analysis
Technical Summary
CVE-2026-74254 is an SQL injection vulnerability (CWE-89) in the Page Builder CK extension for Joomla by joomlack.fr. Versions up to and including 3.6.4 are affected. The flaw resides in the styles model, allowing attackers to inject malicious SQL commands. The vulnerability was addressed in version 3.6.4 for the frontend and version 3.6.5 for the backend, mitigating the injection vector.
Potential Impact
Successful exploitation of this vulnerability could allow an unauthenticated attacker to execute arbitrary SQL commands on the affected Joomla site, potentially leading to data disclosure, data modification, or other impacts consistent with high-severity SQL injection flaws. The CVSS 4.0 score of 9.3 reflects the critical nature of this vulnerability with network attack vector, no required privileges or user interaction, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade the Page Builder CK extension to version 3.6.5 or later to ensure the backend is patched, and at least version 3.6.4 for the frontend. These versions contain official fixes that address the SQL injection vulnerability. No additional mitigation is required once the extension is updated.
CVE-2026-74254: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in joomlack.fr Page Builder CK extension for Joomla
Description
The Joomla extension Page Builder CK versions up to 3.6.4 are vulnerable to an SQL injection flaw affecting the styles model. This vulnerability allows an attacker to execute arbitrary SQL commands due to improper neutralization of special elements in SQL queries. The issue was fixed in version 3.6.5 for the backend and in 3.6.4 for the frontend.
CVSS v4.0
Score 9.3critical
Affected software
joomlack.fr
Page Builder CK extension for Joomla
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-74254 is an SQL injection vulnerability (CWE-89) in the Page Builder CK extension for Joomla by joomlack.fr. Versions up to and including 3.6.4 are affected. The flaw resides in the styles model, allowing attackers to inject malicious SQL commands. The vulnerability was addressed in version 3.6.4 for the frontend and version 3.6.5 for the backend, mitigating the injection vector.
Potential Impact
Successful exploitation of this vulnerability could allow an unauthenticated attacker to execute arbitrary SQL commands on the affected Joomla site, potentially leading to data disclosure, data modification, or other impacts consistent with high-severity SQL injection flaws. The CVSS 4.0 score of 9.3 reflects the critical nature of this vulnerability with network attack vector, no required privileges or user interaction, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade the Page Builder CK extension to version 3.6.5 or later to ensure the backend is patched, and at least version 3.6.4 for the frontend. These versions contain official fixes that address the SQL injection vulnerability. No additional mitigation is required once the extension is updated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Joomla
- Date Reserved
- 2026-08-15T04:38:57.663Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a834478bf8831d5394445d8
Added to database: 08/17/2026, 17:27:20 UTC
Last enriched: 09/12/2026, 01:01:44 UTC
Last updated: 10/02/2026, 02:46:06 UTC
Views: 53
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.