CVE-2026-48908
Summary
A file-upload vulnerability in the JoomShaper SP PageBuilder extension for Joomla, added to CISA's Known Exploited Vulnerabilities catalog on 7 July 2026.
Details
The reported CVSS of 10.0 reflects an unauthenticated path to uploading executable content on a CMS that thousands of small organisations run, and the KEV listing means the flaw was being used rather than merely disclosed. Joomla extension flaws in the page-builder class are the standard route to a web shell on shared hosting, where the site owner often lacks the access to inspect the filesystem. The digest recorded it as part of the 7 July KEV batch; remediation is the extension update plus a check for unfamiliar files under the web root, since upload flaws are frequently exploited before the patch is applied.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-48908 |
| CVSS | 9.8 |
| Vendor / product | JoomShaper (SP PageBuilder, Joomla) |
| Reported in the digest | 2026-07-09 |
Related Pages
Sources: raw/digests/Cyber-Digest-2026-07-09.md