CVE-2026-60029
Received Received - Intake

Authenticated Stored XSS in Quix Page Builder Pro Joomla Extension

Vulnerability report for CVE-2026-60029, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: Joomla! Project

Description

The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for public users.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
joomla quix_page_builder_pro *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Joomla extension Quix Page Builder Pro has an authenticated stored cross-site scripting (XSS) vulnerability. Authenticated users with builder permissions can inject malicious scripts into id or class fields that are rendered for public users.

Detection Guidance

This vulnerability requires authenticated access to the Joomla Quix Page Builder Pro extension. Detection involves checking for stored XSS payloads in id/class fields rendered for public users. Manually inspect Joomla database tables like _quix_page_builder_pro for suspicious JavaScript in fields. Use Joomla admin panel to review builder user activity logs for unauthorized modifications.

Impact Analysis

An attacker with builder access could exploit this to inject scripts that run in the browsers of public users visiting the site. This could lead to data theft, session hijacking, or defacement of the website.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Organizations may face compliance penalties if exploited.

Mitigation Strategies

Update the Quix Page Builder Pro extension to the latest patched version immediately. Disable the extension if no patch is available. Review and restrict access for authenticated builder users to minimize exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-60029. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart