CVE-2026-48908: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Other sources
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48908?
CVE-2026-48908 has a critical severity rating of 10 based on its CVSS score.
How do I fix CVE-2026-48908?
To fix CVE-2026-48908, update the SP Page Builder extension to version 6.6.12 or later.
What type of vulnerability is CVE-2026-48908?
CVE-2026-48908 is a remote code execution vulnerability that allows unauthorized file uploads.
Who is affected by CVE-2026-48908?
CVE-2026-48908 affects users of the SP Page Builder extension for Joomla versions prior to 6.6.12.
What are the potential consequences of CVE-2026-48908?
Exploitation of CVE-2026-48908 can lead to arbitrary PHP code execution on the affected Joomla site.