08 July 2026
Reference: CVE-2026-56290
1. What is being reported?
The Joomlack Page Builder extension for Joomla has a security problem that lets anyone upload files that can run harmful code on your website without needing a username or password. This means hackers can take over your site remotely.
2. What this means in plain English
If your website uses this extension, hackers could gain full control, steal data, or cause damage. This is a high-risk issue because it does not require the attacker to be logged in, making it easier to exploit.
3. Could this affect a small business?
Small businesses, charities, clubs, or any organisation using the Joomlack Page Builder on their Joomla website could be affected. If you do not use this extension or Joomla, this vulnerability does not apply to you.
4. What to do now
- Check if your website uses the Joomlack Page Builder extension.
- Contact your IT provider or website manager immediately to apply any available security updates or mitigations from the vendor.
- If no fix is available, consider disabling or removing the extension until it is safe to use.
- Review your website’s security and monitor for any unusual activity.
5. Ask your IT provider
Can you confirm if our Joomla website uses the Joomlack Page Builder extension, and if so, have the latest security updates or mitigations been applied to protect against CVE-2026-56290?
6. Bottom line
If you use Joomlack Page Builder on your Joomla site, act now to prevent hackers from taking control.
Information based on CISA KEV, NVD, and reputable security reports.