Security
Quix Page Builder SQL injection fixed in version 6.2.2
mySites.guru has disclosed an unauthenticated, error-based SQL injection in ThemeXpert’s Quix Page Builder for Joomla, tracked as CVE-2026-58078 and rated High at CVSS 8.7.
The vulnerability affected Quix Page Builder 6.2.0 and all earlier releases. An anonymous request to a front-end element endpoint could supply a manipulated article ID, allowing database contents to be returned through an error response.
According to mySites.guru, the issue could expose data held in Joomla’s database, including user accounts, password hashes, configuration secrets and site content. The research was reproduced on test installations. The advisory does not report confirmed exploitation of third-party sites, although it found vulnerable versions deployed in the wild.
ThemeXpert addressed the injection in 6.2.1. The vendor subsequently released 6.2.2 with a fix for another reported issue and additional hardening, making it the recommended version for administrators.
Administrators running Quix should update to 6.2.2 immediately and review systems that previously used an affected release. Because the flaw could expose database-held credentials and secrets, site owners should also assess whether those values need to be rotated.
Originally reported by mySites.guru.