SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77993

MEDIUM · CVSS 5.3 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Page Builder CK extension for Joomla is vulnerable to a reflected cross-site scripting (XSS) attack through the iscontenttype parameter in versions prior to 3.6.5. This vulnerability could allow an attacker to execute arbitrary scripts in the context of a user's session, potentially leading to data theft or session hijacking. Joomla administrators using this extension should prioritize applying the latest updates to mitigate the risk.

CVE
CVE-2026-77993
Severity
MEDIUM
CVSS
5.3
EPSS
0.26%

Original NVD Description

Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected XSS via the iscontenttype parameter.