What is CVE-2026-48908?
CVE-2026-48908 is an unrestricted file upload vulnerability in JoomShaper SP Page Builder that allows unauthenticated attackers to upload arbitrary files, leading to PHP code execution. Affected users should immediately update to the latest patched version of the extension.
Azərbaycanca: CVE-2026-48908, JoomShaper SP Page Builder əlavəsində fayl yükləmə zəifliyidir və autentifikasiya olunmamış istifadəçilərə ixtiyari fayllar, o cümlədən PHP kodu yükləməyə və icra etdirməyə imkan verir. Bu zəiflikdən qorunmaq üçün dərhal əlavəni son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434
FAQ1
What does the CVE-2026-48908 vulnerability allow?
CVE-2026-48908 is an unrestricted file upload vulnerability in JoomShaper SP Page Builder that allows unauthenticated attackers to upload arbitrary files, leading to PHP code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.