JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
High Listed in CISA KEV
Summary
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- JoomShaper:SP Page Builder
Sources
- CISA KEV DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2026-48908 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://extensions.joomla.org/extension/sp-page-builder/ reference
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk reference
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk reference
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV