CVE-2026-48908CISA KEVEPSS p99.8%

CVE-2026-48908JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

JoomShaper / SP Page Builder

Description

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

Scoring

CVSS 9.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS88.13% probability of exploitation · percentile 99.8% · 2026-07-28T12:00:27Z
Last modified2026-07-08

CISA KEV entry

Added to KEV: 2026-07-07

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.