Known vulnerability record

CVE-2026-48908

JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

Stable IDcve:CVE-2026-48908Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

Keep the signals separate

CVSS severitycriticalScore 10 · source Joomla
EPSS probability88.1%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-07-07
Ransomware useunknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2026-06-20
CVE modified
2026-08-12
KEV date added
2026-07-07
Dataset fetched
2026-08-21T03:55:07.482Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.