CVE-2026-48909: Joomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4
Published Jun 20, 2026
·Updated
SP LMS (comsplms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server.
Affected Software
1 affected component
JoomShaper SP LMS (com_splms)<4.1.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Joomla extension: SP LMS (com_splms) by JoomShaperto a version that resolves this vulnerability.Fixed in 4.1.4
Event History
Jun 20, 2026
CVE Published
via MITRE·11:56 AM
Data Sourced
via MITRE·11:56 AM
DescriptionWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Jul 6, 2026
Exploit Published
via ExploitDB·12:00 AM
Known Exploited
03:54 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-48909?
The severity of CVE-2026-48909 is critical with a CVSS score of 9.5.
2
How do I fix CVE-2026-48909?
To fix CVE-2026-48909, upgrade the SP LMS extension to version 4.1.4 or later.
3
What type of vulnerability is CVE-2026-48909?
CVE-2026-48909 is a PHP Object Injection vulnerability.
4
What can an attacker do with CVE-2026-48909?
An attacker can execute arbitrary code on the server due to deserialization of user-controlled cookie data.
5
Which versions of JoomShaper SP LMS are affected by CVE-2026-48909?
Versions of JoomShaper SP LMS prior to 4.1.4 are affected by CVE-2026-48909.