Page Builder CK – critical upload flaw, actively exploited
Versió segura: Page Builder CK 3.6.0 or newer · via JoomlaCK
D'un cop d'ull
com_pagebuilderck)De què es tracta?
Page Builder CK is a page builder for Joomla from the French vendor JoomlaCK. It has been around for years and comes in a free edition too, so it is widely deployed – often on sites without dedicated technical support.
One of its upload functions checked neither a login, nor permissions, nor the file type. An attacker could therefore place an executable file on the server without any access at all and then call it – which amounts to a full takeover of the site (CVE-2026-56290, severity 10 out of 10).
The US cyber security agency CISA has listed this flaw in its catalogue of actively exploited vulnerabilities since 7 July 2026. That is not a theoretical rating: being added there requires evidence of real attacks.
An important distinction: Page Builder CK (com_pagebuilderck) is not the same as SP Page Builder by JoomShaper (com_sppagebuilder). Both are page builders, both had critical flaws – but they are different products with different version numbers. Check in your back end which one you run.
M'afecta a mi? – Com comprovar-ho
- Open the back end
Sign in to the Joomla administrator.
- Find the extension
Open Extensions›Manage›Manage and filter for "Page Builder CK" or
pagebuilderck. - Assess the version
If the version is below 3.6.0, the site is vulnerable. In the Joomla 4 line 3.4.10 is the safe release, in the Joomla 3 line 3.1.1.
- Look for signs of a break-in
Search for unknown
.phpfiles in the extension’s media and upload folders, and for super user accounts you did not create yourself.
Com solucionar la vulnerabilitat
- Before updating: back up
Back up files and database before you update, so you can return if anything goes wrong.
- Open the update centre
Go to System›Update›Extensions and click Check for updates.
- Update Page Builder CK
Select the entry and update to 3.6.0 or newer.
- Verify the version
Confirm that the new version is actually installed.
Descàrrega oficial: via JoomlaCK. Assegura't de tenir com a mínim Page Builder CK 3.6.0 or newer.
Ja han atacat el teu lloc web?
Necessites ajuda amb la neteja? Trobaràs professionals qualificats al Directori de proveïdors de serveis de Joomla.
Fonts & més informació
- CVE-2026-56290 – official recordSeverity, affected versions
- CISA – Known Exploited Vulnerabilities CatalogAdded 7 July 2026
- JoomlaCK (vendor)Source of the safe version
Sempre preval la informació oficial de cada desenvolupador. Aquesta pàgina resumeix de manera neutral informació disponible públicament.
Supporters of this site
htprotect.org is a free, vendor-independent information service. It is supported by:

Joomla host from Germany with active community support – discovered the first attack on the JCE vulnerability.
fc-hosting.deSpecialised in cleaning, maintaining and securing Joomla and WordPress websites.
website-bereinigung.deSupport this project
You run a hosting or Joomla service and would like to support htprotect.org – and be listed here as a supporter? Every contribution helps to warn and protect those affected faster.
Prefer to give privately, without a listing? A little something for the tip jar is just as welcome.
Manufactures and installs construction-site signs, hoardings and façade solutions – including design and 3D visualisation.
bauschildundservice.deProfessional IT support from Czechia – Windows management, domain administration and web hosting.
defendersoft.czTravel portal from Germany – package holidays, hotels and flights online, with personal travel-agency advice.
onlineweg.deCreative agency from Brandenburg – web design, print media, photography and 360° panoramas from a single source.
criadero.deIT service provider from Wächtersbach – Joomla websites, PC service, hardware and software.
jahnedv.deInformation-security consulting from Berlin – security analyses, risk management and ISO 27001 for SMEs.
isari-consult.de