What the vulnerability does
01Description
Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in element content, that got executed via view-cache include(). Requires caching on (default).
Explanation of Vulnerability in Simple Terms
02Summary
Quix Page Builder Pro for Joomla contains a code injection vulnerability in versions 1.0-6.2.0. An authenticated administrator can inject and execute arbitrary PHP code through the extension's input handling. This allows complete control over the Joomla site, including data theft, malware installation, and site defacement.
What an attacker can do
03Attacker Capabilities
Run arbitrary PHP code on the Joomla site with full administrative privileges.
Potential impact on your site
04Site Impact
A compromised admin account can be used to inject malicious code, steal data, install backdoors, or take the site offline.
Conditions required to exploit
05Prerequisites
Attacker must have administrator-level access to the Joomla backend.
Key dates
06Disclosure timeline
July 20, 2026
CVE published
July 23, 2026
Record updated