Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Quix 6.3.4 fixes guest access and code execution flaws

ThemeXpert’s Quix Page Builder 6.3.4 addresses multiple security problems that could let guests access restricted content, editors execute server-side code and article text run scripts on Joomla pages.

ThemeXpert released Quix Page Builder 6.3.4 on 30 September 2026. The extension is separate from Joomla core, so the issues affect sites using Quix. mySites.guru published the research based on the vendor’s security changelog.

The affected range is not specified by ThemeXpert. mySites.guru advises treating every version below 6.3.4 as affected. The fixes cover missing access controls for guests, server-side code execution by editors, stored cross-site scripting involving Joomla article content, and hardening for media-related functions.

No CVE identifiers or severity rating were provided for these 6.3.4 issues, and the write-up gives no exploitation status. Earlier Quix security releases referenced CVE-2026-60026 and CVE-2026-60032.

Administrators should update Quix to 6.3.4. Sites running older Quix 6 releases also need the earlier security fixes; installations on older major versions should test the upgrade on a copy first.

Originally reported by mySites.guru.