CVE detail
CVE-2026-48908
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 13.1
Why it matters now
Mention timeline
- Total mentions
- 3
- within the 30d window
- Peak daily
- 2
- highest bucket
Evidence
Source links by recency
8 source links · newest first
at vulnerabilities in Adobe ColdFusion, Langflow, and two Joomla extensions have been exploited in the wild. Tracked as CVE-2026-48282 (CVSS score of 10/10), the ColdFusion bug was flagged as exploited only days after Adobe rolled out patches for it on June 30. It is a path traversal issue that allows attackers to execute arbitrary code. The Langflow s
newswww.securityweek.comJul 8, 2026, 10:45 AMShaper SP Page Builder flaws to its Known Exploited Vulnerabilities (KEV) catalog . The flaws added to the catalog are: CVE-2026-48282 Adobe ColdFusion Path Traversal Vulnerability CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled
newssecurityaffairs.comJul 8, 2026, 8:38 AMee new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled Key Vulnerability CVE-2026-56290 Joomlack Page Builder Improp
governmentwww.cisa.govJul 7, 2026, 12:00 PM- https://www.joomshaper.com/forum/question/45152www.joomshaper.com
No excerpt available.
Issue Trackingwww.joomshaper.comJun 20, 2026, 1:16 PM No excerpt available.
Mitigationwww.cisa.govJun 20, 2026, 1:16 PMNo excerpt available.
Exploitmysites.guruJun 20, 2026, 1:16 PM- https://extensions.joomla.org/extension/sp-page-builder/extensions.joomla.org
No excerpt available.
Productextensions.joomla.orgJun 20, 2026, 1:16 PM - https://www.joomshaper.com/page-builderwww.joomshaper.com
No excerpt available.
Issue Trackingwww.joomshaper.comJun 20, 2026, 1:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
2 repository references · best confidence 0.99 · max 14 stars
- papageo75/CVE-2026-48908-PoCHigh confidencegithubDiscovery source unavailable14 starsDiscovered Jul 9, 2026, 1:19 AM
- Jenderal92/CVE-2026-48908High confidencegithubDiscovery source unavailable2 starsDiscovered Jul 9, 2026, 1:19 AM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-13714CVSS 9.8 · Critical
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an…
- CVE-2026-10818CVSS 8.1 · High
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due…
- CVE-2026-24727CVSS 9.3 · Critical
An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote au…
- CVE-2026-65461CVSS 9.1 · Critical
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
- CVE-2026-65455CVSS 9.1 · Critical
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
- CVE-2026-27064CVSS 9.1 · Critical
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.