CVE-2026-48908
published 2026-06-20CVE-2026-48908: A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP…
PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-07-10
Exploited in the wild
EPSS
14.82%
96.5th percentile
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| joomshaper.net | sp_page_builder_extension_for_joomla | — | — |
| ollyo | sp_page_builder | < 6.6.2 | 6.6.2 |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability allows unauthenticated file upload leading to PHP code execution in SP Page Builder for Joomla; monitor for unexpected PHP file uploads in Joomla SP Page Builder component directories ↗
- →Unauthenticated requests performing file uploads to SP Page Builder endpoints should be flagged; no authentication required means exploit attempts may appear in access logs without session tokens ↗
- ·Vendor advisory and extension details are referenced at the Joomla extensions directory; defenders should consult that source for patched version information ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.010.0CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A vulnerability in the SP Page Builder for Joomla allows the upload of arbitrary files for unauthenticated users, ultimately resulting in PHP code upload and execution.
ghsa_unreviewed·2026-06-20
CVE-2026-48908 [CRITICAL] CWE-284 A vulnerability in the SP Page Builder for Joomla allows the upload of arbitrary files for unauthenticated users, ultimately resulting in PHP code upload and execution.
A vulnerability in the SP Page Builder for Joomla allows the upload of arbitrary files for unauthenticated users, ultimately resulting in PHP code upload and execution.
VulDB
joomshaper SP Page Builder extension for Joomla 1.0.0-6.6.1 on Joomla access control (EUVD-2026-38110)
vuldb·2026-06-20·CVSS 10.0
CVE-2026-48908 [CRITICAL] joomshaper SP Page Builder extension for Joomla 1.0.0-6.6.1 on Joomla access control (EUVD-2026-38110)
A vulnerability labeled as critical has been found in joomshaper SP Page Builder extension for Joomla 1.0.0-6.6.1 on Joomla. Affected is an unknown function of the component SP Page. Such manipulation leads to improper access controls.
This vulnerability is documented as CVE-2026-48908. The attack can be executed remotely. There is not any exploit available.
VulnCheck
ollyo sp_page_builder Improper Access Control
vulncheck·2026·CVSS 9.8
CVE-2026-48908 [CRITICAL] ollyo sp_page_builder Improper Access Control
ollyo sp_page_builder Improper Access Control
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Affected: ollyo sp_page_builder
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/
Exploit PoC: https://vulncheck.com/xdb/e28c557bcdbd; https://vulncheck.com/xdb/e3958f7a3201
CISA
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
cisa·2026-07-07·CVSS 9.8
CVE-2026-48908 [CRITICAL] CWE-434 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
Vulnerability: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
Affected: JoomShaper SP Page Builder
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's in
No detection rules found.
Nuclei
Joomla SP Page Builder <= 6.6.1 - Unauthenticated Arbitrary File Upload RCE
nuclei·CVSS 9.8
CVE-2026-48908 [CRITICAL] Joomla SP Page Builder <= 6.6.1 - Unauthenticated Arbitrary File Upload RCE
Joomla SP Page Builder >>1)):(c>>>1);}crc=(crc>>>8)^c;}return (crc^(-1))>>>0;}
function sb(s){var a=[];for(var i=0;i>>8)&0xFF];}
function u32(n){return [n&0xFF,(n>>>8)&0xFF,(n>>>16)&0xFF,(n>>>24)&0xFF];}
function pp(d,a){for(var i=0;i>>2);r+=t.charAt(((x&3)>>4));r+=(i+1>>6)):"=";r+=(i+2<b.length)?t.charAt(z&63):"=";}return r;}
function rtok(n){var c="abcdefghijklmnopqrstuvwxyz0123456789",s="";for(var i=0;i<n;i++){s+=c.charAt(Math.floor(Math.random()*c.length));}return s;}
function buildZip(files){var out=[],cd=[],off=0,dt=0x0000,dd=0x0021;for(var i=0;i<files.length;i++){var f=files[i],nb=sb(f.name),crc=crc32(f.data),sz=f.data.length,nl=nb.length;var lh=[];pp(lh,[0x50,0x4B,0x03,0x04]);pp(lh,u16(20));pp(lh,u16(0));pp(lh,u16(0));pp(lh,u16(dt));pp(lh,u16(dd));pp(lh,u32(crc));pp(lh,u32(sz));pp(
Hackernews
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
blogs_hackernews·2026-07-08·CVSS 10.0
CVE-2026-48282 [CRITICAL] CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, citing evidence of active exploitation.
The vulnerabilities are listed below -
CVE-2026-48282 (CVSS score: 10.0) - A path traversal vulnerability in Adobe ColdFusion that could lead to arbitrary code execution in the context of the current user.
CVE-2026-56290 (CVSS score: 10.0) - An improper access control vulnerability in Joomlack Page Builder that could allow for remote code execution via unaut
Hackernews
New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
blogs_hackernews·2026-07-02
CVE-2025-64446 New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC , travels in Python proof-of-concept (PoC) repositories on GitHub that claim to exploit hot new CVEs.
Run one, and it quietly lifts your saved passwords, browser cookies, and files, then hands the attacker a shell on your machine. YesWeHack and Sekoia published their joint findings on July 1 and warned that, as of that report, the malware and its servers were still live, so do not run any of these PoCs.
2026-06-20
Published
2026-07-07
Added to CISA KEV
Exploited in the wild