CVE-2026-48908 - JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
- Severity
- critical
- Product
- JoomShaper SP Page Builder
- Published
- 2026-07-07
- EPSS
- 0.885
- CISA KEV
- Known exploited
- Ransomware
- Known campaign use
References and validation
- https://github.com/search?q=CVE-2026-48908&type=repositories
- https://nvd.nist.gov/vuln/detail/CVE-2026-48908
Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.