VYPR
Critical severity9.8CISA KEVNVD Advisory· Published Jun 20, 2026· Updated Jul 8, 2026

CVE-2026-48908

CVE-2026-48908

Description

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3

Patches

Vulnerability mechanics

References

5

News mentions

6