CVE-2026-60028
HIGHJoomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1
Title source: cnaDescription
Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin viewing the page. Unescaped output + unsanitised SVG.
References (1)
Core 1
Core References
Product product
https://www.themexpert.com/quix-pagebuilder
Scores
CVSS v4
8.6
EPSS
0.0025
EPSS Percentile
16.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-79
Status
published
Products (1)
themexpert.com/Quix Page Builder Pro extension for Joomla
1.0-6.2.0
Published
Jul 20, 2026
Tracked Since
Jul 21, 2026