Skip to content
COOEY

FAIL › dossier

SP Page Builder

PRODUCT

· dossier confidence 20%

SP Page Builder, a Joomla extension, has experienced notable security vulnerabilities, including critical remote code execution flaws.

PROFILE
CategorysoftwareWhat they doSP Page Builder is a Joomla extension that provides a visual drag-and-drop page builder for creating websites. Websitehttps://www.joomshaper.com/ ↗
SECURITY POSTURE

The security posture of SP Page Builder appears to be compromised based on the internal failure history and external evidence.

Notable failures
  • CVE-2026-48908 (high [RCE0day])
  • CVE-2026-48908 (critical [RCE0day])
Patterns: unauthenticated RCE exploits
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2026-07-07 CVE-2026-48908 high JoomShaper SP Page Builder allows unauthenticated users to upload and execute arbitrary PHP files.
2026-06-20 CVE-2026-48908 critical A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Open questions: What is the current security posture of SP Page Builder? · How are the vulnerabilities being addressed?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-06 03:43:49.796366+00:00