PT-2026-61675 · Themexpert.Com · Quix Page Builder Pro Extension For Joomla

CVE-2026-60028

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin viewing the page. Unescaped output + unsanitised SVG.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-60028

Affected Products

Quix Page Builder Pro Extension For Joomla