[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":44,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":51,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":57,"vulnerability-29781":64},[4,15,21,27,33,39],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[11],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":16,"slug":17,"text":18,"link":8,"external":9,"targets":19,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[20],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":22,"slug":23,"text":24,"link":8,"external":9,"targets":25,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[26],"\u002Ffeatures\u002Fpentest-reporting",{"title":28,"slug":29,"text":30,"link":8,"external":9,"targets":31,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[32],"\u002Ffeatures\u002Fintegrations",{"title":34,"slug":35,"text":36,"link":8,"external":9,"targets":37,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[38],"\u002Fexploit-helpers\u002Fsniper",{"title":40,"slug":14,"text":41,"link":8,"external":9,"targets":42,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Homepage","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.",[43],"\u002F",["Island",45],{"key":46,"params":47,"result":49},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":48},"{}",{"head":50},{},["Island",52],{"key":53,"params":54,"result":55},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":48},{"head":56},{},["Island",58],{"key":59,"params":60,"result":62},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":61},"{\"text-color\":\"gray\"}",{"head":63},{},{"id":65,"detectable_with":66,"vuln_details":72,"vuln_id":97,"name":98,"published":99,"updated":99},29781,{"tool":67,"engine":70},{"id":68,"name":69},1,"Network Scanner",{"id":68,"name":71},"Sniper",{"id":65,"codename":73,"description":74,"severity":75,"risk_description":76,"public_description":77,"public_recommendation":78,"recommendation":79,"references":80,"cvssv3":85,"epss_score":86,"epss_percentile":87,"cve":88,"in_cisa_catalog":90,"date":91,"software_type":92,"vendor":93,"product":94,"ptt_exploit_capabilities":95},null,"We found that the target Joomla site is running the Page Builder CK extension, versions up to and including 3.5.10, which is vulnerable to an unauthenticated remote code execution. The vulnerability stems from a missing authentication check and a disabled file-type allow-list in the image handling feature (com_pagebuilderck, task=browse.ajaxAddPicture): an unauthenticated attacker can submit a crafted multipart\u002Fform-data request to the upload endpoint and store an arbitrary file, including executable PHP, under the attacker-controlled web-accessible path (for example media\u002Fcom_pagebuilderck\u002Fgfonts\u002F) without any file-type or content validation. Because the uploaded file is stored in a location directly served by the web server, the attacker can execute arbitrary code by requesting the uploaded file directly.","critical","The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network.","The Page Builder CK extension for Joomla, versions up to and including 3.5.10, is vulnerable to unauthenticated remote code execution due to an unrestricted file upload in its image handling feature. An attacker can submit a crafted multipart\u002Fform-data request to the upload endpoint (com_pagebuilderck, task=browse.ajaxAddPicture) and store a PHP file under a web-accessible directory. Because the endpoint requires no authentication and performs insufficient validation, the uploaded PHP file can be requested and executed remotely.","Update the Page Builder CK extension to version 3.6.0 or later.","We recommend updating the Page Builder CK extension to version 3.6.0 or later; if immediate update is not possible, disable or restrict the extension and ensure uploaded files are stored outside a web-executable location.",[81,82,83,84],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-56290","https:\u002F\u002Fcxsecurity.com\u002Fissue\u002FWLB-2026070010","https:\u002F\u002Fwww.exploit-db.com\u002Fexploits\u002F52626","https:\u002F\u002Fwww.cisa.gov\u002Fknown-exploited-vulnerabilities-catalog",9.8,0.30866,0.98205,[89],"CVE-2026-56290",true,"2026-06-29T00:00:00Z","Joomla Extension","Joomlack","Page Builder CK",[96],"RCE","NETSCAN-SNIPER-CVE-2026-56290","Joomla Page Builder CK - Remote Code Execution","2026-09-29T00:00:00Z"]