Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-23 · updated: 2026-09-23 · tags: [cve] · confidence: high · severity: critical · affected_sectors: [technology, retail] · au_impact: false

CVE-2026-48908

Summary

A file-upload vulnerability in the JoomShaper SP PageBuilder extension for Joomla, added to CISA's Known Exploited Vulnerabilities catalog on 7 July 2026.

Details

The reported CVSS of 10.0 reflects an unauthenticated path to uploading executable content on a CMS that thousands of small organisations run, and the KEV listing means the flaw was being used rather than merely disclosed. Joomla extension flaws in the page-builder class are the standard route to a web shell on shared hosting, where the site owner often lacks the access to inspect the filesystem. The digest recorded it as part of the 7 July KEV batch; remediation is the extension update plus a check for unfamiliar files under the web root, since upload flaws are frequently exploited before the patch is applied.

Attribute Detail
CVE CVE-2026-48908
CVSS 9.8
Vendor / product JoomShaper (SP PageBuilder, Joomla)
Reported in the digest 2026-07-09

Related Pages

Sources: raw/digests/Cyber-Digest-2026-07-09.md