Page Builder CK – critical upload flaw, actively exploited
Versione sicura: Page Builder CK 3.6.0 or newer · via JoomlaCK
In sintesi
com_pagebuilderck)Di cosa si tratta?
Page Builder CK is a page builder for Joomla from the French vendor JoomlaCK. It has been around for years and comes in a free edition too, so it is widely deployed – often on sites without dedicated technical support.
One of its upload functions checked neither a login, nor permissions, nor the file type. An attacker could therefore place an executable file on the server without any access at all and then call it – which amounts to a full takeover of the site (CVE-2026-56290, severity 10 out of 10).
The US cyber security agency CISA has listed this flaw in its catalogue of actively exploited vulnerabilities since 7 July 2026. That is not a theoretical rating: being added there requires evidence of real attacks.
An important distinction: Page Builder CK (com_pagebuilderck) is not the same as SP Page Builder by JoomShaper (com_sppagebuilder). Both are page builders, both had critical flaws – but they are different products with different version numbers. Check in your back end which one you run.
Il mio sito è interessato? – Come verificarlo
- Open the back end
Sign in to the Joomla administrator.
- Find the extension
Open Extensions›Manage›Manage and filter for "Page Builder CK" or
pagebuilderck. - Assess the version
If the version is below 3.6.0, the site is vulnerable. In the Joomla 4 line 3.4.10 is the safe release, in the Joomla 3 line 3.1.1.
- Look for signs of a break-in
Search for unknown
.phpfiles in the extension’s media and upload folders, and for super user accounts you did not create yourself.
Come risolvere la vulnerabilità
- Before updating: back up
Back up files and database before you update, so you can return if anything goes wrong.
- Open the update centre
Go to System›Update›Extensions and click Check for updates.
- Update Page Builder CK
Select the entry and update to 3.6.0 or newer.
- Verify the version
Confirm that the new version is actually installed.
Download ufficiale: via JoomlaCK. Assicurati di avere almeno Page Builder CK 3.6.0 or newer.
Il sito è già stato attaccato?
Ti serve aiuto per ripulire il sito? Trovi professionisti qualificati nella Directory dei fornitori di servizi Joomla.
Fonti & approfondimenti
- CVE-2026-56290 – official recordSeverity, affected versions
- CISA – Known Exploited Vulnerabilities CatalogAdded 7 July 2026
- JoomlaCK (vendor)Source of the safe version
Fanno sempre fede le informazioni ufficiali del rispettivo sviluppatore. Questa pagina riassume in modo neutrale informazioni pubblicamente disponibili.
Supporters of this site
htprotect.org is a free, vendor-independent information service. It is supported by:

Joomla host from Germany with active community support – discovered the first attack on the JCE vulnerability.
fc-hosting.deSpecialised in cleaning, maintaining and securing Joomla and WordPress websites.
website-bereinigung.deSupport this project
You run a hosting or Joomla service and would like to support htprotect.org – and be listed here as a supporter? Every contribution helps to warn and protect those affected faster.
Prefer to give privately, without a listing? A little something for the tip jar is just as welcome.
Manufactures and installs construction-site signs, hoardings and façade solutions – including design and 3D visualisation.
bauschildundservice.deProfessional IT support from Czechia – Windows management, domain administration and web hosting.
defendersoft.czTravel portal from Germany – package holidays, hotels and flights online, with personal travel-agency advice.
onlineweg.deCreative agency from Brandenburg – web design, print media, photography and 360° panoramas from a single source.
criadero.deIT service provider from Wächtersbach – Joomla websites, PC service, hardware and software.
jahnedv.deInformation-security consulting from Berlin – security analyses, risk management and ISO 27001 for SMEs.
isari-consult.de