Feed/CVE-2026-48908
CVE-2026-48908CRITICALCVSS 9.8CISA KEV: Actively Exploited

CVE-2026-48908

Published Jun 20, 2026·Updated Jul 8, 2026

NVD Description

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

Public Exploits & PoCs9 found

[POC] GHSA-3mgp-fx93-9xv5 — CVE-2026-48908

CVE-2026-48908

1

[POC] GHSA-652q-gvq3-74qv — CVE-2026-48908-Joomla-SP-Page-Builder-RCE

Technical analysis and advisory for CVE-2026-48908: Unauthenticated Arbitrary File Upload to RCE in JoomShaper SP Page Builder.

1

[POC] GHSA-3mgp-fx93-9xv5 — CVE-2026-48908-PoC

Unauthenticated RCE PoC for CVE-2026-48908 — SP Page Builder for Joomla (≤ 6.6.1): arbitrary file upload via asset.uploadCustomIcon. Self-cleaning, token-guarded. Authorized testing only.

1

PoC: CVE-2026-48908-by-yora

Passive security checker for CVE-2026-48908 affecting SP Page Builder.

1

[POC] GHSA-3mgp-fx93-9xv5 — CVE-2026-48908-SP-Page-Builder-Joomla

CVE-2026-48908 - SP Page Builder Joomla Unauthenticated RCE

[POC] GHSA-3mgp-fx93-9xv5 — CVE-2026-48908

Unauthenticated RCE PoC for CVE-2026-48908 SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning support.

[POC] CVE-2026-48908 — CVE-2026-48908

CVE-2026-48908 — PoC exploit for unauthenticated RCE in SP Page Builder (Joomla) via arbitrary file upload. Multi‑threaded, case‑bypass, shell verification. For authorized security testing only.

[POC] MAL-2026-2307 — CVE-2026-48908

Unauthenticated RCE PoC for CVE-2026-48908 SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning support.

PoC: CVE-2026-48908-joomla-sp-page-builder-detection

Laboratory validation of CVE-2026-48908 in Joomla SP Page Builder, covering unauthorized icon upload, PHP file write, code execution as www-data, auditd and PCAP evidence, event timeline reconstruction, and SOC detection recommendations. Includes Polish and English reports.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free