CRITICAL
CVE-2026-48908
CVSS
9.8
KEV
Description
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Summary dbcve.org
SP Page Builder for Joomla contains an unauthenticated arbitrary file upload vulnerability that allows remote attackers to upload malicious files, including PHP scripts, to the affected system, potentially leading to remote code execution.
Mitigation
Immediately restrict or disable file upload functionality in SP Page Builder, apply vendor security patches if available, and implement strict file type validation and authentication requirements for upload endpoints.
Weakness (CWE)
CWE-434
Unrestricted File Upload
EPSS Score
15.09%
Probability of exploitation in next 30 days
96.6th percentile
References
https://www.joomshaper.com/page-builder
Product
https://extensions.joomla.org/extension/sp-page-builder/
Product
https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48908
US Government Resource
https://www.joomshaper.com/forum/question/45152
Issue Tracking
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.