A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
References
| Link | Resource |
|---|---|
| https://www.joomshaper.com/page-builder | Product |
| https://extensions.joomla.org/extension/sp-page-builder/ | Product |
| https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/ | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48908 | US Government Resource |
| https://www.joomshaper.com/forum/question/45152 | Issue Tracking |
Configurations
History
No history.
Information
Published : 2026-06-20 13:16
Updated : 2026-07-08 13:57
NVD link : CVE-2026-48908
Mitre link : CVE-2026-48908
CVE.ORG link : CVE-2026-48908
JSON object : View
Products Affected
ollyo
- sp_page_builder
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
