Unrated severityCISA KEVNVD Advisory· Published Jun 20, 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.12
CVE-2026-48908
Description
A vulnerability in the SP Page Builder for Joomla allows the upload of arbitrary files for unauthenticated users, ultimately resulting in PHP code upload and execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- www.joomshaper.com/page-buildermitreproduct
News mentions
6- CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla FlawsSecurityWeek · Jul 8, 2026
- CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEVThe Hacker News · Jul 8, 2026
- New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit ReposThe Hacker News · Jul 2, 2026
- ChocoPoc malware delivered via trojanized exploits on GitHubBleepingComputer · Jul 1, 2026
- New ChocoPoC malware targets researchers via trojanized PoC exploitsBleepingComputer · Jul 1, 2026
- CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA Alerts