CVE-2026-60031 MEDIUM

CVE-2026-60031: Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1

Vendor Themexpert.com
Product Quix Page Builder Pro extension for Joomla
Weakness CWE-200 · Info exposure
Published July 20, 2026
Last update July 23, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw exceptions reflected in AJAX handler responses.

Explanation of Vulnerability in Simple Terms

02Summary

The Quix Page Builder Pro extension for Joomla contains an information exposure vulnerability that allows unauthenticated attackers to access sensitive data over the network. The vulnerability requires no user interaction and can be exploited remotely. Site administrators should update to a patched version when available.

What an attacker can do

03Attacker Capabilities

Read sensitive information from the site without authentication.

Potential impact on your site

04Site Impact

Unauthorized users can access confidential data stored or processed by the Quix Page Builder Pro extension.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

July 20, 2026 CVE published
July 23, 2026 Record updated

Related vulnerabilities

08Related CVE