CVE-2026-48908: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-07-07. EPSS: 88.5% chance of exploitation in the next 30 days.

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

Affected products

  • Ollyo SP Page Builder: before 6.6.2 (fixed in 6.6.2)

Published 2026-06-20. Last modified 2026-10-07.