CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-56290

KEV Critical · CVSS 9.8

Page Builder CK (Joomla extension) — Unauthenticated arbitrary file upload leading to Remote Code Execution (RCE)

CVSS
9.8
nvd
EPSS
83.3%
100th pct
KEV
Listed
2026-07-07
Class
other
CWE-434, CWE-434

Description

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Search profile — drives PoC discovery

Symbols com_pagebuilderckuploadpbckfile upload handlerexecutable file uploadJoomla component
Keywords CVE-2026-56290Page Builder CKPageBuilderCKJoomla file upload RCEPBCK unauthenticated uploadjoomlack file uploadCWE-434 Joomlaarbitrary file upload Joomla extension PoCpagebuilderck RCE exploit
Versions: <UNKNOWN>

Ranked PoCs (3) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-03T00:00:43.000Z · profiled 2026-07-03T00:30:43.000Z