Skip to content
COOEY

EXPOSURES › CVE-2026-48908

CVE-2026-48908

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-07-07 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-48908 ↗
⚡ RCE ◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildsupply-chainzero-day

JoomShaper SP Page Builder allows unauthenticated users to upload and execute arbitrary PHP files.

This vulnerability enables remote code execution via file upload, posing a severe risk to any DIB organization using the product for FedRAMP or NIST 800-171 compliance. Immediate removal of the product from production environments and a full security audit of all deployed instances are required to prevent unauthorized access to sensitive data.

Shame score — An unauthenticated RCE vulnerability in a widely used SaaS product represents a critical failure in input validation and security controls.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.