Critical severity9.8CISA KEVNVD Advisory· Published Jun 20, 2026· Updated Jul 8, 2026
CVE-2026-48908
CVE-2026-48908
Description
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
5- mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/nvdThird Party Advisory
- extensions.joomla.org/extension/sp-page-builder/nvdProduct
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
- www.joomshaper.com/forum/question/45152nvdIssue Tracking
- www.joomshaper.com/page-buildernvdProduct
News mentions
6- CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla FlawsSecurityWeek · Jul 8, 2026
- CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEVThe Hacker News · Jul 8, 2026
- New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit ReposThe Hacker News · Jul 2, 2026
- ChocoPoc malware delivered via trojanized exploits on GitHubBleepingComputer · Jul 1, 2026
- New ChocoPoC malware targets researchers via trojanized PoC exploitsBleepingComputer · Jul 1, 2026
- CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA Alerts