Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote

Quix Page Builder security vulnerabilities

mySites.guru tracks 3 vulnerabilities in com_quix. Every connected Joomla site is checked against them on each audit, and flagged if it runs an affected version.

What we check for

Quix Page Builder (com_quix) below 6.2.2 - CVE-2026-58078 (CVSS 8.7) Unauthenticated SQL Injection (database read), Code Execution, Path Traversal and Stored XSS

Quix Page Builder before 6.2.1 contains an unauthenticated SQL injection in the joomla-article builder element. An article id taken directly from a request parameter is concatenated into a database query with no integer cast or escaping, and the AJAX handler reflects the database error back to the caller, so an anonymous attacker with no login and no CSRF token can read arbitrary data from the site database, including user password hashes and the Joomla secret. This is the error-based kind of injection, so the data returns in the response rather than having to be inferred a bit at a time. Discovered and reported to ThemeXpert by mySites.guru (Phil Taylor), and confirmed against the Quix Pro 6.2.0 release. It is tracked as CVE-2026-58078, assigned by the Joomla CNA (CVSS 4.0 8.7, High), crediting Phil Taylor of mySites.guru as the finder. Quix 6.2.1 fixes this by casting the id to an integer before it reaches the query. Quix 6.2.1 also fixes five further security issues reported by mySites.guru in the same disclosure: a code-execution path via the Raw HTML element (PHP tags in element content are now neutralised), a path traversal and arbitrary file read in the Form element submission handler, stored XSS through the icon field including inline SVG, a missing permission check on the admin media manager endpoint, and the reflection of internal error details in front-end AJAX responses. ThemeXpert shipped 6.2.1 on 15 July 2026, the same day the issues were reported, and also hardened the bundled JMedia media manager in 1.6.1 (blocking executable and polyglot uploads and remote-URL SSRF, sanitising uploaded SVG, and serving files with hardened headers). Fix: update Quix to 6.2.1 or later, and update JMedia to 1.6.1 or later if installed. One update closes all six issues. A web application firewall with SQL injection filtering enabled will block the injection payload, but that buys time and is not a fix. Also covered by this rule, all affecting Quix Page Builder Pro 1.0 to 6.2.0 and fixed in the same release: CVE-2026-60026 (authenticated PHP code execution via element content executed through the view-cache include, requires caching on, which is the default), CVE-2026-60027 (unauthenticated path traversal via form elements allowing arbitrary file read, requires a published page with a Form element), CVE-2026-60028 and CVE-2026-60029 (authenticated stored XSS via unescaped output, unsanitised SVG and id/class fields that render for public users), CVE-2026-60030 (authenticated users could upload media regardless of their media management permissions) and CVE-2026-60031 (information disclosure through raw exceptions reflected in AJAX handler responses).

Affected versions: ≥ 1.0.0 and < 6.2.2

Full advisory: our disclosure post

Quix Page Builder (com_quix) 6.2.2 to 6.2.6 - Unauthenticated SQL Injection, Page Creation and Session Tampering

Quix Page Builder versions 6.2.2 to 6.2.6 contain security flaws that ThemeXpert fixed across two later releases, according to the vendor's own changelog. Quix 6.2.4 fixed unauthenticated page creation using only a CSRF token (which Joomla gives to anonymous visitors), missing permission checks on collection rename and publish by ID, page and collection creation silently overwriting an existing record, and a quixlogin cookie-guessing login fallback that was replaced with a signed, time-limited token. Quix 6.2.7 fixed a SQL injection vulnerability in the Joomla Articles element, blocked unauthorised changes to session and cookie data, and updated bundled libraries with security fixes. No CVE has been published for these fixes at the time of writing. Update Quix to the latest version (6.2.7 or later). Sites below 6.2.2 are covered by the separate CVE-2026-58078 rule.

Affected versions: ≥ 6.2.2 and < 6.2.7

Full advisory: github.com

Quix Page Builder (com_quix) 6.2.7 to 6.3.3 - Unauthenticated Settings Change and Restricted Page Disclosure, Authenticated Code Execution and Stored XSS

Quix Page Builder versions before 6.3.4 contain several security flaws that ThemeXpert fixed in 6.3.4 (released 30 Sep 2026). Unauthenticated visitors could change Quix settings and read pages that are restricted by access level. A user with editor access to Quix pages could run code on the server. Text taken from Joomla articles, including titles and categories, was output unescaped on Quix pages, allowing stored XSS. Pasted-image handling, image resizing and the bundled JMedia media manager were also hardened. No CVE has been assigned yet. Earlier versions are covered by the separate Quix rules for below 6.2.2 and 6.2.2 to 6.2.6, and are also affected by these issues. Update to Quix 6.3.4 or later.

Affected versions: ≥ 6.2.7 and < 6.3.4

Full advisory: our disclosure post

What we have written about Quix Page Builder

Running Quix Page Builder on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

CVE identifiers: CVE-2026-58078, CVE-2026-60026, CVE-2026-60027, CVE-2026-60028, CVE-2026-60029, CVE-2026-60030, CVE-2026-60031. Rules current as of 3 October 2026.