CVE-2026-48908

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ollyo:sp_page_builder:*:*:*:*:-:joomla\!:*:*

History

08 Jul 2026, 13:57

Type Values Removed Values Added
References () https://extensions.joomla.org/extension/sp-page-builder/ - () https://extensions.joomla.org/extension/sp-page-builder/ - Product
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48908 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48908 - US Government Resource

07 Jul 2026, 19:16

Type Values Removed Values Added
References
  • () https://extensions.joomla.org/extension/sp-page-builder/ -
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48908 -

05 Jul 2026, 15:16

Type Values Removed Values Added
CWE CWE-284

30 Jun 2026, 18:47

Type Values Removed Values Added
First Time Ollyo
Ollyo sp Page Builder
CWE CWE-434
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://www.joomshaper.com/page-builder - () https://www.joomshaper.com/page-builder - Product
References () https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/ - () https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/ - Third Party Advisory
References () https://www.joomshaper.com/forum/question/45152 - () https://www.joomshaper.com/forum/question/45152 - Issue Tracking
CPE cpe:2.3:a:ollyo:sp_page_builder:*:*:*:*:-:joomla\!:*:*

24 Jun 2026, 19:17

Type Values Removed Values Added
References
  • () https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/ -
  • () https://www.joomshaper.com/forum/question/45152 -

21 Jun 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-20 13:16

Updated : 2026-07-08 13:57


NVD link : CVE-2026-48908

Mitre link : CVE-2026-48908

CVE.ORG link : CVE-2026-48908


JSON object : View

Products Affected

ollyo

  • sp_page_builder
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type