Skip to content
COOEY

FAIL › dossier

Joomlack

VENDOR

· dossier confidence 33%

Joomlack is a French software vendor providing Joomla extensions, including the Page Builder CK extension, which has been flagged by CISA for critical unauthenticated RCE vulnerabilities. The vendor has a critical security posture with two related CVEs added to the KEV catalog within 10 days, indicating a pattern of delayed patching and active exploitation.

PROFILE
CategorySoftware VendorWhat they doJoomlack is a software vendor specializing in Joomla extensions, specifically the Page Builder CK extension. Websitehttps://www.joomlack.fr/en/joomla-extensions/page-builder-ck ↗
SECURITY POSTURE

Critical security posture with two unauthenticated RCE vulnerabilities in the same extension within a 10-day window, flagged by CISA as actively exploited and added to the KEV catalog.

Notable failures
  • CVE-2026-56290: Unauthenticated RCE via arbitrary file upload
  • CVE-2026-56290: Critical severity RCE in Page Builder CK
  • CISA KEV inclusion for Joomlack Page Builder
  • Federal remediation deadline missed or imminent (July 10, 2026)
Patterns: Repeated unpatched edge-device RCEs; Improper access control in web platforms
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2026-07-07 CVE-2026-56290 high Joomlack Page Builder allows unauthenticated remote code execution via arbitrary file upload.
2026-06-29 CVE-2026-56290 critical The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Open questions: Joomlack's internal failure history indicates repeated vulnerabilities in the same extension, suggesting a systemic issue with their security patching process. · The company's lack of public financial data or employee count limits understanding of their organizational security maturity.
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-14 04:01:57.607524+00:00