CVE-2026-56290
KEV Critical · CVSS 9.8Page Builder CK (Joomla extension) — Unauthenticated arbitrary file upload leading to Remote Code Execution (RCE)
- CVSS
- 9.8
- nvd
- EPSS
- 83.3%
- 100th pct
- KEV
- Listed
- 2026-07-07
- Class
- other
- CWE-434, CWE-434
Description
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Search profile — drives PoC discovery
Symbols com_pagebuilderckuploadpbckfile upload handlerexecutable file uploadJoomla component
Keywords CVE-2026-56290Page Builder CKPageBuilderCKJoomla file upload RCEPBCK unauthenticated uploadjoomlack file uploadCWE-434 Joomlaarbitrary file upload Joomla extension PoCpagebuilderck RCE exploit
Versions: <UNKNOWN>
Ranked PoCs (3) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 3
- ★ 3
- ★ 1
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
Status: enriched · ingested 2026-07-03T00:00:43.000Z · profiled 2026-07-03T00:30:43.000Z