cbcvebase.
CVE-2026-48908
published 2026-06-20

CVE-2026-48908: A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP…

PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-07-10
Exploited in the wild
EPSS
14.82%
96.5th percentile
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

Affected

2 ranges
VendorProductVersion rangeFixed in
joomshaper.netsp_page_builder_extension_for_joomla
ollyosp_page_builder< 6.6.26.6.2

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability allows unauthenticated file upload leading to PHP code execution in SP Page Builder for Joomla; monitor for unexpected PHP file uploads in Joomla SP Page Builder component directories
  • Unauthenticated requests performing file uploads to SP Page Builder endpoints should be flagged; no authentication required means exploit attempts may appear in access logs without session tokens
  • ·Vendor advisory and extension details are referenced at the Joomla extensions directory; defenders should consult that source for patched version information

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.010.0CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.