CVE-2026-48908

A vulnerability in the SP Page Builder for Joomla allows the upload of arbitrary files for unauthenticated users, ultimately resulting in PHP code upload and execution.

Scoring

Severity
CRITICAL
CVSS base score
10
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red
EPSS probability
14.82%
CISA KEV
Known exploited vulnerability
CWE
CWE-284, CWE-434
Published
2026-06-20
Last modified
2026-08-12

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs