Known vulnerability record
CVE-2026-48908
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
Summary
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Signals
Keep the signals separate
CVSS severitycriticalScore 10 · source Joomla
EPSS probability88.1%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-07-07
Ransomware useunknownPreserved as known / unknown, not a truthy default
Timeline
Dates and provenance
- CVE published
- 2026-06-20
- CVE modified
- 2026-08-12
- KEV date added
- 2026-07-07
- Dataset fetched
- 2026-08-21T03:55:07.482Z
Sources
Original records
- https://www.cve.org/CVERecord?id=CVE-2026-48908 ↗
- https://nvd.nist.gov/vuln/detail/CVE-2026-48908 ↗
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48908 ↗
Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.