Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-56290

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.833
EPSS Ranking 99.6%
CVSS Severity
CVSS v3 Score 9.8
Proposed Action
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
Ransomware Campaign
Unknown
Products affected by CVE-2026-56290


Contact Us

Shodan ® - All rights reserved