The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin viewing the page. Unescaped output + unsanitised SVG.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.themexpert.com/quix-pagebuilder |
|
History
Mon, 20 Jul 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Jul 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin viewing the page. Unescaped output + unsanitised SVG. | |
| Title | Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Joomla
Published: 2026-07-20T18:09:33.059Z
Updated: 2026-07-21T05:33:35.062Z
Reserved: 2026-07-08T05:31:35.889Z
Link: CVE-2026-60028
Updated: 2026-07-20T20:12:24.496Z
No data.
No data.