JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
July 31, 2026 · CISA · Severity: CRITICAL
JoomShaper SP Page Builder, a popular website builder for Joomla, has a critical vulnerability (CVE-2026-48908) that allows unauthenticated attackers to upload arbitrary files, including malicious PHP code, leading to remote code execution. CISA confirmed the flaw is actively being exploited in the wild and added it to their Known Exploited Vulnerabilities catalog on July 7, 2026. This affects all versions of SP Page Builder prior to the patched release. The vulnerability poses a severe risk to websites using the unpatched SP Page Builder plugin, as attackers can gain full control over affected systems without authentication. Organizations using Joomla with this plugin should immediately update to the latest version to mitigate the threat. CISA recommends treating this as a high-priority issue due to active exploitation and the potential for complete system compromise.
Key Takeaways
- CVE-2026-48908 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
- The vulnerability involves privilege escalation or authentication bypass, granting unauthorized access to sensitive functions.
- CISA BOD 26-04 requires remediation within the specified due date — apply vendor mitigations promptly.
- JoomShaper SP Page Builder: JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.