CVE-2026-48909: Joomshaper.net SP Lms Extension For Joomla
Critical severity, CVSS 9.5. EPSS: 4.9% chance of exploitation in the next 30 days.
SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server.
Affected products
- Joomshaper.net SP Lms Extension For Joomla: version 1.0.0-4.1.3 only
Published 2026-06-20. Last modified 2026-06-22.