CVE-2026-48908: JoomShaper SP Page Builder
EPSS88.5%No. 489 of 1739 in KEV
CVE year2026listed the same year
Same vendor in KEV1
Same product1
| Field | Value |
|---|---|
| Vendor | JoomShaper |
| Product | SP Page Builder |
| Name | JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability |
| Added to KEV | 2026-07-07 |
| US federal due date | 2026-07-10 |
| Ransomware use | Unknown |
| CWE | CWE-434 |
CISA description
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A JoomShaper SP Page Builder vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-07.