Опубликовано: 20 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10
CVSS3: 9.8
Описание
A vulnerability in the SP Page Builder for Joomla allows the upload of arbitrary files for unauthenticated users, ultimately resulting in PHP code upload and execution.
A vulnerability in the SP Page Builder for Joomla allows the upload of arbitrary files for unauthenticated users, ultimately resulting in PHP code upload and execution.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-48908
- https://extensions.joomla.org/extension/sp-page-builder
- https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48908
- https://www.joomshaper.com/forum/question/45152
- https://www.joomshaper.com/page-builder
EPSS
Процентиль: 100%
0.8813
Высокий
10 Critical
CVSS4
9.8 Critical
CVSS3
CVE ID
Дефекты
CWE-284
CWE-434
Связанные уязвимости
CVSS3: 9.8
nvd
около 1 месяца назад
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
CVSS3: 9.8
fstec
около 2 месяцев назад
Уязвимость конструктора страниц SP Page Builder системы прикладного программного обеспечения JoomShaper, позволяющая нарушителю выполнить произвольный код
EPSS
Процентиль: 100%
0.8813
Высокий
10 Critical
CVSS4
9.8 Critical
CVSS3
CVE ID
Дефекты
CWE-284
CWE-434