CVE-2026-48908
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
- Affected products
- Wp Page Builder
- Ollyo Sp Page Builder
- < 6.6.2
- Fix
- Available
- CVSS 4.0
- 10.0 CRITICAL
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 88.1% (100th percentile)
- Weakness
- CWE-434
- NVD status
- Analyzed
- Published
- 2026-06-20
- Attack patterns
- CAPEC-242
- Entry point
- custom_icon request body
- Path
- index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon
CVE-2026-48908 at NVD
7 known exploits for CVE-2026-48908
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Unrestricted Upload of File with Dangerous Type in Ollyo Sp_Page_Builder
Exploit for Unrestricted Upload of File with Dangerous Type in Ollyo Sp_Page_Builder
Exploit for Unrestricted Upload of File with Dangerous Type in Ollyo Sp_Page_Builder
Exploit for Unrestricted Upload of File with Dangerous Type in Ollyo Sp_Page_Builder
Exploit for CVE-2026-48908
Exploit for CVE-2026-48908
Exploit for CVE-2026-48908