{"id":"CVE-2026-48908","title":"A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.","summary":"A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-434"],"vendor":"ollyo","product":"sp_page_builder","affected":["sp_page_builder < 6.6.2"],"patched":["sp_page_builder 6.6.2"],"published":"2026-06-20","updated":"2026-10-07","sourceUpdated":"2026-10-07T19:17:38.030","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-48908","references":[{"url":"https://www.joomshaper.com/page-builder","label":"security@joomla.org"},{"url":"https://extensions.joomla.org/extension/sp-page-builder/","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48908","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.joomshaper.com/forum/question/45152","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available","cve.org"],"epss":0.88512,"epssPercentile":0.99771,"kev":true,"kevDateAdded":"2026-07-07","kevDueDate":"2026-07-10","kevRansomware":false,"exploited":true,"exploits":{"github":11,"githubRepos":["https://github.com/papageo75/CVE-2026-48908-PoC","https://github.com/Jenderal92/CVE-2026-48908","https://github.com/0xBlackash/CVE-2026-48908"],"nuclei":["javascript/cves/2026/CVE-2026-48908"],"checkedAt":"2026-10-07T20:47:22.833Z"},"exploitAvailable":true,"ssvc":{"exploitation":"active","automatable":"yes","technicalImpact":"total","timestamp":"2026-07-08T03:56:38.663940Z"},"scores":{"nvd":9.8,"cna":10},"ingestedAt":"2026-10-07T18:42:20.901Z","slug":"CVE-2026-48908","body":"## Overview\n\nA vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.\n\n## Affected\n\n- `sp_page_builder < 6.6.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `sp_page_builder 6.6.2`","depth":"hadal","depthScore":97,"depthScoreParts":{"impact":53.9,"likelihood":17.7,"exploitation":25,"ransomware":0},"changes":[{"seq":217696,"id":"CVE-2026-48908","ts":1791406335804,"field":"cvss","old":"10","new":"9.8"}]}