Affected versions: ≥ 3.1.1 and < 3.1.4
Full advisory: our disclosure post
Joomla extension security alerts (26 Aug) Sourcerer 16.0.0Fabrik 4.7.2ZOO: unauth RCEJCE 2.9.99.10
Page Builder CK ships three separate release branches: 3.1.x for Joomla 3, 3.4.x for Joomla 4, and 3.6.x for Joomla 5 and 6. This rule covers the Joomla 3 branch. CVE-2026-63048 (CVSS 9.4) is an arbitrary file upload in the browse.ajaxAddPicture endpoint: the uploaded filename is not validated against any extension allow-list, so a user holding core.edit (Editor and above under default Joomla permissions) can write an executable .php file and run it. The vendor fixed this on the Joomla 5/6 branch in 3.6.3, by adding an extension allow-list together with Joomla MediaHelper::canUpload(). That fix has not been backported to the Joomla 3 branch. The 3.1.3 release of 25 August 2026 carried the styles SQL injection fix only, and the upload allow-list is still absent from 3.1.3, so 3.1.3 remains affected. The published affected range for CVE-2026-63048 is 1.0.0 to 3.6.2, which already includes every 3.1.x build. There is currently NO fixed version available on the Joomla 3 branch, so this is not a case of being behind on updates. The route to a patched build is to migrate the site to Joomla 5 or 6 and install Page Builder CK 3.6.5. Until then, restrict which user groups hold core.edit on com_pagebuilderck, and block requests carrying task=browse.ajaxAddPicture at the WAF or reverse proxy. If the vendor later ships 3.1.4 with the allow-list restored, this rule clears on its own. Note the linked article is written on 3.6.x numbering, because the Joomla 5/6 branch is where the flaw was first fixed.
Affected versions: ≥ 3.1.1 and < 3.1.4
Official record: cve.org · NVD
Every connected Joomla site is checked against these rules on each audit, and flagged if it runs an affected version.
Affected versions: ≥ 3.1.1 and < 3.1.4
Full advisory: our disclosure post
Page Builder CK - Page Builder CK (com_pagebuilderck) 3.3.0 to 3.4.12 - Authenticated Arbitrary File Upload (RCE)
Page Builder CK ships three separate release branches: 3.1.x for Joomla 3, 3.4.x for Joomla 4, and 3.6.x for Joomla 5 and 6. This rule covers the Joomla 4 branch. CVE-2026-63048 (CVSS 9.4) is an arbitrary file upload in the browse.ajaxAddPicture endpoint: the uploaded filename is not validated against any extension allow-list, so a user holding core.edit (Editor and above under default Joomla permissions) can write an executable .php file and run it. The vendor fixed this on the Joomla 5/6 branch in 3.6.3, by adding an extension allow-list together with Joomla MediaHelper::canUpload(). That fix has not been backported to the Joomla 4 branch. The 3.4.12 release of 25 August 2026 carried the styles SQL injection fix only, and the upload allow-list is still absent from 3.4.12, so 3.4.12 remains affected. The published affected range for CVE-2026-63048 is 1.0.0 to 3.6.2, which already includes every 3.4.x build. There is currently NO fixed version available on the Joomla 4 branch, so this is not a case of being behind on updates. The route to a patched build is to migrate the site to Joomla 5 or 6 and install Page Builder CK 3.6.5. Until then, restrict which user groups hold core.edit on com_pagebuilderck, and block requests carrying task=browse.ajaxAddPicture at the WAF or reverse proxy. If the vendor later ships 3.4.13 with the allow-list restored, this rule clears on its own. Note the linked article is written on 3.6.x numbering, because the Joomla 5/6 branch is where the flaw was first fixed.
Affected versions: ≥ 3.3.0 and < 3.4.13
Full advisory: our disclosure post
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
Rules current as of 26 August 2026.