Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-48908

Published 2026-06-20
Updated 2 months ago
Vendor/s
JoomShaper
Product/s
SP Page Builder
Version/s
* > 6.6.2
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.8
/ 10
Critical
Severity Details
Base score
9.8 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-48908 is a critical 9.8 CVSS vulnerability in JoomShaper SP Page Builder allowing unauthenticated RCE. Update to version 6.6.2 immediately.

CPE

JoomShaper logo
JoomShaper
Product Version Start Version End (excl.) Status
sp_page_builder * 6.6.2 vulnerable

Related weakness (CWE)

CWE-434, CWE-434

Remediation plan

1

Apply official patches

Immediately download and install the latest security updates provided by JoomShaper for SP Page Builder to address the underlying unauthenticated file upload vulnerability.

2

Update affected systems

Ensure that all instances of SP Page Builder are updated to version 6.6.2 or later. Audit all Joomla environments to identify and upgrade any installations running vulnerable versions.

3

Restrict access

Implement Web Application Firewall (WAF) rules to block unauthorized POST requests to SP Page Builder upload endpoints and restrict access to the Joomla administrative interface to trusted IP addresses.

4

Monitor for exploitation

Conduct a forensic review of web directories for unauthorized PHP files, especially in media or upload folders, and monitor web server logs for suspicious unauthenticated file upload attempts.

Detection Guidance

"Monitor web server access logs for unusual POST requests targeting SP Page Builder components, specifically looking for unauthenticated traffic. Security teams should search for the presence of unexpected .php files within image or media upload directories. Deploying WAF signatures to detect arbitrary file upload patterns and auditing Joomla logs for unauthorized configuration changes can help identify potential exploitation attempts associated with this critical vulnerability."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management