CVE detail
CVE-2026-56290
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 12.2
Why it matters now
Mention timeline
- Total mentions
- 8
- within the 30d window
- Peak daily
- 4
- highest bucket
Evidence
Source links by recency
8 source links · newest first
at vulnerabilities in Adobe ColdFusion, Langflow, and two Joomla extensions have been exploited in the wild. Tracked as CVE-2026-48282 (CVSS score of 10/10), the ColdFusion bug was flagged as exploited only days after Adobe rolled out patches for it on June 30. It is a path traversal issue that allows attackers to execute arbitrary code. The Langflow s
newswww.securityweek.comJul 8, 2026, 10:45 AMShaper SP Page Builder flaws to its Known Exploited Vulnerabilities (KEV) catalog . The flaws added to the catalog are: CVE-2026-48282 Adobe ColdFusion Path Traversal Vulnerability CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled
newssecurityaffairs.comJul 8, 2026, 8:38 AMExploit Database Exploits GHDB Papers Shellcodes Search EDB SearchSploit Manual Submissions Online Training Stats About Us About Exploit-DB Exploit-DB History FAQ Search Joomla Page Builder CK 3.5.10 - Arbitrary File Upload EDB-ID: 52626 CVE: 2026-56290 EDB Verified: Author: M@rAz Ali Type: webapps Exploit: / Platform: Multiple Date: 2026-07-08 Vulnerable App: # Exploit Title: Joomla Page Builder CK 3.5.10 - Arbitrary File Upload # Google Dork: inurl:com_pagebuilderck OR "/components/com_pagebui
exploitwww.exploit-db.comJul 8, 2026, 12:00 AMee new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled Key Vulnerability CVE-2026-56290 Joomlack Page Builder Improp
governmentwww.cisa.govJul 7, 2026, 12:00 PMNo excerpt available.
Mitigationwww.cisa.govJun 29, 2026, 3:16 PMNo excerpt available.
Exploitmysites.guruJun 29, 2026, 3:16 PM- https://forum.joomlack.fr/index.php/page-builder-ck/21627-nouvelle-version-de-pbck-et-joomla-3forum.joomlack.fr
No excerpt available.
Patchforum.joomlack.frJun 29, 2026, 3:16 PM - https://www.joomlack.fr/www.joomlack.fr
No excerpt available.
Productwww.joomlack.frJun 29, 2026, 3:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
2 repository references · best confidence 0.99 · max 3 stars
- shinthink/pbck-exploitHigh confidencegithubDiscovery source unavailable3 starsDiscovered Jul 9, 2026, 1:19 AM
- Jenderal92/CVE-2026-56290High confidencegithubDiscovery source unavailable3 starsDiscovered Jul 9, 2026, 1:19 AM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-13714CVSS 9.8 · Critical
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an…
- CVE-2026-10818CVSS 8.1 · High
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due…
- CVE-2026-24727CVSS 9.3 · Critical
An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote au…
- CVE-2026-65461CVSS 9.1 · Critical
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
- CVE-2026-65455CVSS 9.1 · Critical
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
- CVE-2026-27064CVSS 9.1 · Critical
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.