vulnti.work

JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

High Listed in CISA KEV
CVECVE-2026-48908
First seen2026-07-07 00:00 UTC
Disclosed2026-07-07 00:00 UTC
Last updated2026-07-14 19:30 UTC
Channel statuspending_review

Summary

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Affected products

  • JoomShaper:SP Page Builder

Sources

  • CISA KEV DATABASE

Original Links

Timeline

  1. kev_added CISA KEV
  2. kev_ingest CISA KEV