HIGHVulnerability
Verified
Global

CISA KEV: JoomShaper SP Page Builder — JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

Analysis

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. Added to CISA Known Exploited Vulnerabilities catalog on 2026-07-07. Remediation due: 2026-07-10.

Indicators of Compromise (1)

CVE (1)
CVE-2026-48908
Source Attribution

Originally published by CISA KEV on Jul 7, 2026. Verified by: CISA.

Related Threats