Skip to main content
Change Risk Intel

CVE-2026-48908 — JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

CVSS
9.8 (Critical)
KEV status
CISA KEV — Listed
First seen (CISA KEV)
Recommended change window
Emergency change — SP Page Builder is a widespread Joomla builder; patch within 48 hours or take the affected site offline.
Affected products
JoomShaper SP Page Builder

Why this one matters to a CAB

SP Page Builder is one of the two or three most-installed Joomla page builders in the world. An unauthenticated file upload here is not a niche CVE — it is a mass-exploitation event in progress. If your Joomla footprint uses SP Page Builder, assume the site was targeted the day the advisory dropped.

Defender’s angle

  • Emergency response, not routine patch: SP Page Builder is common enough that scan-and-exploit worms follow disclosure within hours. Treat this as an incident-response event with a change record attached, not the reverse.
  • Rollback readiness: the JoomShaper update sequence occasionally breaks custom SP Page Builder templates. Snapshot the Joomla /templates/ directory and the site database before the update.
  • Follow-up hygiene: rotate the Joomla super-user password and every FTP/SFTP credential associated with the site after the patch; the assumption is that credentials in memory or config files during the exposure window are burned.

What to bring to CAB

An IR-led change record. The change is the patch; the incident is the pre-patch exposure window. Do not close the incident until the webshell scan is clean.

Sources

This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.