CVE-2026-48908
CRITICAL KEVJoomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.12
Title source: cnaExploitation Summary
CVE-2026-48908 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 7, 2026. EIP tracks 10 public exploits from researchers including papageo75, g0thamRabb1t, cazzysoci.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-48908, an unauthenticated RCE vulnerability in SP Page Builder for Joomla. The exploit leverages a case-sensitive blocklist bypass to upload a malicious ZIP file containing a PHP shell and .htaccess file, achieving remote code execution.
Description
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Exploits (10)
This repository contains a functional exploit for CVE-2026-48908, an unauthenticated RCE vulnerability in SP Page Builder for Joomla. The exploit leverages a case-sensitive blocklist bypass to upload a malicious ZIP file containing a PHP shell and .htaccess file, achieving remote code execution.
This repository provides a detailed technical analysis of CVE-2026-48908, a remote code execution vulnerability in Joomla SP Page Builder. It includes evidence of exploitation (screenshots, logs, and reports) but intentionally omits exploit code, focusing on detection, validation, and mitigation guidance.
This PoC exploits an arbitrary file upload vulnerability in Joomla's SPPB Page Builder component (CVE-2026-48908) by crafting a malicious ZIP file containing a PHP web shell disguised as an icon font asset. The exploit bypasses extension checks and uploads the shell to a predictable path for remote code execution.
The repository contains only a markdown file listing multiple external GitHub repositories and a backup link to an encrypted archive, with no actual exploit code or technical analysis. The external links and encrypted backup are red flags for potential social engineering or malware distribution.
This exploit targets an unauthenticated file upload vulnerability in SP Page Builder (Joomla) versions 1.0.0-6.6.1, allowing remote code execution via a crafted ZIP archive containing a PHP web shell. The exploit bypasses case-sensitive filename filters by using mixed-case extensions (.PHP) and verifies shell accessibility post-upload.
This exploit targets CVE-2026-48908, an unauthenticated remote code execution vulnerability in SP Page Builder (Joomla) versions ≤6.6.1. It abuses an improper access control flaw in the `asset.uploadCustomIcon` task to upload a malicious ZIP file containing a PHP webshell, achieving code execution via adaptive methods (direct PHP upload or .htaccess bypass).
This repository contains a functional exploit for CVE-2026-48908, targeting an unauthenticated RCE vulnerability in SP Page Builder. The exploit uploads a malicious ZIP file containing a PHP shell, bypasses authentication, and achieves remote code execution via multiple methods (direct PHP extensions or .htaccess manipulation).
The repository contains a functional Python exploit for CVE-2026-48908, which targets an unauthenticated file upload vulnerability in SP Page Builder for Joomla (<= 6.6.1). The exploit crafts a malicious ZIP file to upload a PHP webshell, achieving remote code execution (RCE).
This repository contains a functional exploit for CVE-2026-48908, targeting SP Page Builder for Joomla. The exploit leverages unauthenticated file upload via the `asset.uploadCustomIcon` task to achieve remote code execution by uploading a malicious ZIP file containing a PHP shell.
The repository contains only a README with minimal information about CVE-2026-48908, claiming an unauthenticated RCE in SP Page Builder for Joomla, but lacks any technical details, exploit code, or proof-of-concept. The absence of substantive content and reliance on vague claims suggest a potential lure.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H