Skip to main content

SP Page Builder vulnerabilities

1 published alerts for JoomShaper SP Page Builder.

Actively exploited (KEV)

CVE-2026-48908

JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

JoomShaper SP Page Builder is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-48908). JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. CISA remediation due date: 2026-07-10. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.