Feed/CVE-2026-4890
CVE-2026-4890HIGHCVSS 7.5

CVE-2026-4890

Published May 11, 2026·Updated Aug 25, 2026

NVD Description

A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

Public Exploits & PoCs10 found

[POC] GHSA-652q-gvq3-74qv — CVE-2026-48908-Joomla-SP-Page-Builder-RCE

Technical analysis and advisory for CVE-2026-48908: Unauthenticated Arbitrary File Upload to RCE in JoomShaper SP Page Builder.

1

[POC] GHSA-3mgp-fx93-9xv5 — CVE-2026-48908-PoC

Unauthenticated RCE PoC for CVE-2026-48908 — SP Page Builder for Joomla (≤ 6.6.1): arbitrary file upload via asset.uploadCustomIcon. Self-cleaning, token-guarded. Authorized testing only.

1

[POC] GHSA-3mgp-fx93-9xv5 — CVE-2026-48908

CVE-2026-48908

1

[POC] CVE-2026-48908 — CVE-2026-48908

CVE-2026-48908 — PoC exploit for unauthenticated RCE in SP Page Builder (Joomla) via arbitrary file upload. Multi‑threaded, case‑bypass, shell verification. For authorized security testing only.

[POC] MAL-2026-2307 — CVE-2026-48907

CVE-2026-48907 – Joomla JCE Unauthenticated Remote Code Execution (RCE)

[POC] MAL-2026-2307 — CVE-2026-48908

Unauthenticated RCE PoC for CVE-2026-48908 SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning support.

[POC] GHSA-2j8v-hwgc-x698 — CVE-2026-48907

POC for CVE-2026-48907

[POC] MAL-2026-2307 — masta-cve-2026-48907

cve-2026-48907 scanner

[POC] MAL-2026-2307 — CVE-2026-48907

CVE-2026-48907 is a CVSS 10.0 pre-auth RCE in Joomla Content Editor affecting all versions ≤ 2.9.99.4. The Grayxploit team breaks down the 3-weakness chain — missing auth, no extension validation, and an unsafe upload flag — that lets attackers pop a shell in 3 HTTP requests.

[POC] GHSA-2j8v-hwgc-x698 — CVE-2026-48907

CVE-2026-48907 PoC

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free