CVE-2026-48909: Joomshaper.net SP Lms Extension For Joomla

Critical severity, CVSS 9.5. EPSS: 4.9% chance of exploitation in the next 30 days.

SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server.

Affected products

Published 2026-06-20. Last modified 2026-06-22.