CVE-2026-48908 — JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
- CVSS
- 9.8 (Critical)
- KEV status
- CISA KEV — Listed
- First seen (CISA KEV)
- Recommended change window
- Emergency change — SP Page Builder is a widespread Joomla builder; patch within 48 hours or take the affected site offline.
- Vendor advisory
- https://extensions.joomla.org/extension/sp-page-builder/
- Affected products
- JoomShaper SP Page Builder
Why this one matters to a CAB
SP Page Builder is one of the two or three most-installed Joomla page builders in the world. An unauthenticated file upload here is not a niche CVE — it is a mass-exploitation event in progress. If your Joomla footprint uses SP Page Builder, assume the site was targeted the day the advisory dropped.
Defender’s angle
- Emergency response, not routine patch: SP Page Builder is common enough that scan-and-exploit worms follow disclosure within hours. Treat this as an incident-response event with a change record attached, not the reverse.
- Rollback readiness: the JoomShaper update sequence occasionally
breaks custom SP Page Builder templates. Snapshot the Joomla
/templates/directory and the site database before the update. - Follow-up hygiene: rotate the Joomla super-user password and every FTP/SFTP credential associated with the site after the patch; the assumption is that credentials in memory or config files during the exposure window are burned.
What to bring to CAB
An IR-led change record. The change is the patch; the incident is the pre-patch exposure window. Do not close the incident until the webshell scan is clean.
Sources
This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.