ThemeXpert Quix Page Builder Unauthenticated SQL Injection Vulnerability

Vulnerability

A vulnerability allowing unauthenticated SQL injection has been identified in the Quix Page Builder Pro extension for Joomla. This issue is present in version 6.2.0 and all prior releases. The vulnerability arises from a front-end AJAX endpoint that processes article IDs from anonymous requests. The endpoint fails to properly sanitize the IDs before using them in database queries, allowing an anonymous visitor to manipulate the input and extract data from any database table. This includes sensitive information such as user accounts, password hashes, and other Joomla API secrets. The vulnerability has been confirmed to allow complete database read access through error-based SQL injection, where the database error messages are reflected back to the attacker, facilitating data extraction.

Impact

Exploitation of this vulnerability allows an anonymous user to read the entire Joomla database, including all user accounts and password hashes. This read access is error-based, meaning the data is extracted through crafted SQL injection that exploits database error messages, one value per request.

Remediation

Users are advised to update Quix Page Builder to version 6.2.1, which fixes the SQL injection vulnerability by properly sanitizing the article ID before it is used in database queries. After updating, it is recommended to clear Joomla's cache and any CDN or page cache to ensure that stale front-end assets do not linger.

Added: Jul 16, 2026, 9:26 AM
Updated: Jul 16, 2026, 9:26 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
9.7
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.