CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-48908

Critical · CVSS 9.8

SP Page Builder for Joomla — Unauthenticated Arbitrary File Upload leading to Remote Code Execution (RCE)

CVSS
9.8
nvd
EPSS
0.73%
50th pct
KEV
No
Class
other
CWE-434, CWE-434

Description

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

Search profile — drives PoC discovery

Symbols uploadcustomiconSP Page Buildercom_sppagebuilderuploadfile_uploadphp_uploadcustomicon
Keywords CVE-2026-48908SP Page BuilderJoomla arbitrary file uploaduploadcustomicon RCESP Page Builder unauthenticated uploadcom_sppagebuilder RCEJoomla SP Page Builder exploitSP Page Builder zero dayJoomShaper file upload vulnerabilityCWE-434 Joomla SP Page Builder
Versions: <UNKNOWN>

Ranked PoCs (9) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-01T00:00:14.000Z · profiled 2026-07-01T18:30:14.000Z