Junglewise Threat Intelligence

CVE-2026-48908: JoomShaper SP Page Builder arbitrary file upload in Joomla

CVE-2026-48908 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2026-06-20

Technologies: JoomShaper SP Page Builder. Vendors: JoomShaper.

Executive brief

JoomShaper SP Page Builder, a popular tool for building websites on the Joomla platform, contains a critical security flaw that allows anyone on the internet to upload files to the server without logging in. An attacker can use this to upload malicious scripts and take full control of the website. This vulnerability has been reported as being actively exploited in the wild, posing an immediate risk to site operations and data security.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in the SP Page Builder extension for Joomla. The flaw allows unauthenticated remote attackers to bypass security checks and upload arbitrary files, including PHP scripts, to the web server. This is achieved via a network request to a vulnerable component, such as the 'uploadcustomicon' function. Successful exploitation leads to Remote Code Execution (RCE) with the privileges of the web server user. The vulnerability is reportedly being exploited in the wild as a zero-day. Users should update to version 6.6.2 or later to remediate the issue.

Affected products

  • JoomShaper SP Page Builder extension for Joomla 1.0.0 through 6.6.1

Timeline

  • 2026-06-20: disclosed: Initial disclosure by Joomla! Project
  • 2026-06-20: advisory: NVD published date
  • 2026-06-22: exploited: Reported as exploited in the wild (zero-day)
  • 2026-06-30: patched: Fix identified in version 6.6.2

Related threats