Skip to main content

CVE detail

CVE-2026-48908

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

CVSS 10.0 · CriticalBuzz score 80.0KEV listed2 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 80.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 22.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 13.1
Mention score
22.0
8 evidence mentions in the snapshot
Diversity score
20.0
7 sources across 6 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
13.1
2 repos · best confidence 0.99
Best PoC traction
14
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
3
within the 30d window
Peak daily
2
highest bucket

Evidence

Source links by recency

Newest mentions first
8 source links · newest first

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

2 repository references · best confidence 0.99 · max 14 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-13714

    The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an…

    CVSS 9.8 · Critical
    1 mention
  • CVE-2026-10818

    The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due…

    CVSS 8.1 · High
    2 mentions
  • CVE-2026-24727

    An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote au…

    CVSS 9.3 · Critical
    1 mention
  • CVE-2026-65461

    Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.

    CVSS 9.1 · Critical
    1 mention
  • CVE-2026-65455

    Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.

    CVSS 9.1 · Critical
    1 mention
  • CVE-2026-27064

    Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.

    CVSS 9.1 · Critical
    1 mention