AI description
CVE-2026-48908 is a vulnerability identified in JoomShaper's SP Page Builder for Joomla. This flaw allows unauthenticated users to upload arbitrary files, which can ultimately lead to the execution of PHP code on the affected system. This vulnerability is categorized as an unrestricted upload of a file with a dangerous type, and it has been added to CISA's Known Exploited Vulnerabilities Catalog, indicating that it is being actively exploited.
- Description
- A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
- Source
- security@joomla.org
- NVD status
- Analyzed
- Products
- sp_page_builder
CVSS 4.0
- Type
- Secondary
- Base score
- 10
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red
- Severity
- CRITICAL
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
- Exploit added on
- Jul 7, 2026
- Exploit action due
- Jul 10, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Hype score
- Not currently trending
JoomShaper SP Page Builder (CVE-2026-48908) と Joomlack Page Builder (CVE-2026-56290) のRCEにつながるファイルアップロード脆弱性、KEV是正期限は7/10で過ぎています。未適用環境は依然と...
@Joe_Biden_ja
12 Jul 2026
22 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Two Joomla page-builder extensions, two CVSS 10.0 unauthenticated file-upload → RCE bugs, both added to CISA KEV on the same day (Jul 7). CVE-2026-48908 (SP Page Builder) + CVE-2026-56290 (PageBuilder CK). Exploited in the wild. Patching ≠ done. 🧵 https://t.co/xjbd2dfDzG
@zerohuntai
11 Jul 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CISA added three new vulnerabilities to its KEV Catalog: CVE-2026-48908, CVE-2026-55255, CVE-2026-56290, due to active exploitation https://t.co/VlW8laFu3k
@f1tym1
9 Jul 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA added three new vulnerabilities to its KEV Catalog: CVE-2026-48908, CVE-2026-55255, CVE-2026-56290, due to active exploitation https://t.co/gset4o5XQI
@f1tym1
8 Jul 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISAが既知の悪用された脆弱性3件をカタログに追加 CISA Adds Three Known Exploited Vulnerabilities to Catalog #CISA (Jul 7) CVE-2026-48908 JoomShaper SP Page Builderにおける危険なタイプのファイルの無制限アップロードの脆弱性 CVE-2
@foxbook
8 Jul 2026
232 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国CISA¹の既知の悪用された脆弱性カタログに3件と1件の追加。JoomShaper SP Page BuilderのCVE-2026-48908、LangflowのCVE-2026-55255、Joomlack Page BuilderのCVE-2026-56290とColdfusionのCVE-2026-48282。対処期限は3日。ランサム悪用不知。
@__kokumoto
7 Jul 2026
750 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ We added JoomShaper SP Page Builder vulnerability CVE-2026-48908, Bernoulli denklemi vulnerability CVE-2026-55255, & Joomlack Page Builder vulnerability CVE-2026-56290 to our KEV Catalog. Visit https://t.co/7S6bozvJuc & apply mitigations to protect your org from c
@FarukCakicil65
7 Jul 2026
10 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
🛡️ We added JoomShaper SP Page Builder vulnerability CVE-2026-48908, Langflow vulnerability CVE-2026-55255, & Joomlack Page Builder vulnerability CVE-2026-56290 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattack
@CISACyber
7 Jul 2026
5869 Impressions
3 Retweets
15 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CRITICAL: CVE-2026-48908 (CVSS 9.8) - SP Page Builder for Joomla allows unauthenticated arbitrary file upload & PHP code execution. Patch immediately! #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/lBHocpJeOQ
@DFIR_Lab
5 Jul 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Top CVEs w/ public exploits (Jun 20–27): CVE-2026-48908 Joomla SPB RCE (exploited live) CVE-2026-48909 Joomla SP LMS PHP Obj injection CVE-2026-12417 SignUp/In admin takeover CVE-2026-12416 Invoice Generator takeover CVE-2026-39938 Cacti LFI Protect via https://t.co/ZUTqqMjQUp
@exploitgrid
27 Jun 2026
1601 Impressions
4 Retweets
19 Likes
7 Bookmarks
2 Replies
0 Quotes
CVE-2026-48908 Arbitrary File Upload and PHP Code Execution in SP Page Builder for Joomla https://t.co/vnmLtU2qPR
@VulmonFeeds
20 Jun 2026
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ollyo:sp_page_builder:*:*:*:*:-:joomla\\!:*:*",
"matchCriteriaId": "357A3AA5-76BB-4E60-AA71-CB8FB76E2221",
"versionEndExcluding": "6.6.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]