What is CVE-2026-74254?
A SQL injection vulnerability was found in the Page Builder CK extension for Joomla before version 3.6.5, related to the styles model. The issue was fixed in the frontend with version 3.6.4 and in the backend with version 3.6.5. Users are strongly advised to update to the latest version immediately.
Azərbaycanca: Joomla üçün Page Builder CK genişlənməsinin 3.6.5-dən əvvəlki versiyalarında SQL injection zəifliyi aşkarlanıb. Bu boşluq styles modeli ilə bağlıdır və arxa və ön hissədə müxtəlif versiyalarda aradan qaldırılıb. İstifadəçilərə dərhal ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which component is affected by CVE-2026-74254 in Page Builder CK?
The vulnerability is related to the styles model.
In which version was this SQL injection vulnerability fixed in the backend of Page Builder CK?
The issue was fixed in the backend with version 3.6.5.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.