LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-48908: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 7, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 10, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-48908 to its Known Exploited Vulnerabilities catalog on Jul 7, 2026, with a federal patch deadline of Jul 10, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and…

JoomShaper SP Page Builder contains an unrestricted upload vulnerability that lets unauthenticated users upload arbitrary files, including PHP code that the server may then execute. The issue is tracked as CVE-2026-48908 and is classified under CWE-434.

Because the upload path requires no authentication, remote attackers can reach the flaw directly over the network, making prompt identification and remediation important for any site running the affected component.

How it works

The weakness belongs to the class of unrestricted file-upload vulnerabilities. The application accepts files without sufficiently validating their type or content, allowing an attacker to supply a file with a dangerous extension or MIME type.

Am I affected? How to find it in your systems

SP Page Builder is a Joomla component; inventory should therefore begin with a scan of all Joomla installations and their installed extensions. Confirm the presence and version of the JoomShaper SP Page Builder package against the vendor advisory, because only specific releases are affected.

How to remediate

Apply the vendor-supplied update referenced in the official advisory. After patching, review the component configuration to ensure that file-type validation and directory restrictions remain enabled.

If you can't patch immediately

Until the update can be applied, reduce exposure by limiting network access to the Joomla administration and front-end upload paths. Place the site behind a web-application firewall rule that inspects uploads for executable content and blocks requests lacking valid session tokens.

If your data may have been exposed

Actively exploited upload vulnerabilities have led to unauthorized access and data exposure in other products. Organizations can run a free exposure scan of their domains and email addresses against known breach data to determine whether any credentials or assets have already appeared in public records.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedJoomShaper · SP Page Builder
WeaknessCWE-434
Added to CISA KEVJul 7, 2026
Federal patch deadlineJul 10, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities