Security
Loading…

CVE-2026-48908

CRITICALCVSS 9.8Known Exploited
Description

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

Timeline
Published:June 20th, 2026 5:16 PM
Last modified:July 8th, 2026 5:57 PM
Added to KEV:July 7th, 2026
CVSS Scoring

CVSS v3: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

ollyo

Products

sp_page_builder
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute