CVE-2026-60027

Summary

The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticated users frontend users are allowed traversal paths and read arbitrary files. Requires a published page with a Form element.

Affected Software

VendorProductVersion RangeStatus
themexpert.comQuix Page Builder Pro extension for Joomla1.0-6.2.0affected

Weaknesses

  • CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory

References