CVSS
9.8
CVSS v3.1
EPSS
83.3%
Exploit Prediction Score
Published
June 29, 2026
Exploitability
Exploited in the wild (CISA KEV)
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).