CVE-2026-48908
CRITICALA vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Published: 6/20/2026Modified: 7/8/2026
Related Intelligence (0)
No articles currently reference this CVE.
References (5)
https://www.joomshaper.com/page-builderProducthttps://extensions.joomla.org/extension/sp-page-builder/Producthttps://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/Third Party Advisoryhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48908US Government Resourcehttps://www.joomshaper.com/forum/question/45152Issue Tracking