CVE-2026-48908: listed in the CISA KEV catalog CVE-2026-48908 · EPSS 88% · KEV 2026-07-07
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Is CVE-2026-48908 exploited? Listed in the CISA KEV catalog on 2026-07-07. Federal remediation due 2026-07-10. Past that date by 36 days. EPSS puts exploitation in the next 30 days at 88%. Public exploit code: none found in monitored sources. Public detection rules exist. Which products and versions are affected? No affected package list recorded here yet.
Is there a patch? No patch identifier recorded here yet.
What PlainSec published about CVE-2026-48908 Primary sources What this record does not say No CVSS score from NVD. No affected package data. No patch identifier. KEV and EPSS are re-checked daily. Record last updated 2026-08-11.
CVE-2026-48908: listed in the CISA KEV catalog CVE-2026-48908 · EPSS 88% · KEV 2026-07-07
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Is CVE-2026-48908 exploited? Listed in the CISA KEV catalog on 2026-07-07. Federal remediation due 2026-07-10. Past that date by 36 days. EPSS puts exploitation in the next 30 days at 88%. Public exploit code: none found in monitored sources. Public detection rules exist. Which products and versions are affected? No affected package list recorded here yet.
Is there a patch? No patch identifier recorded here yet.
What PlainSec published about CVE-2026-48908 Primary sources What this record does not say No CVSS score from NVD. No affected package data. No patch identifier. KEV and EPSS are re-checked daily. Record last updated 2026-08-11.