{"data":{"cve_id":"CVE-2026-48908","severity":"CRITICAL","cvss":9.8,"cvss_version":"3.1","kev":true,"epss":0.8813,"epss_percentile":0.99753,"published":"2026-06-20","vendor":"ollyo","product":"Sp Page Builder","description":"A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.","url":"https://dbcve.org/cve/CVE-2026-48908","enrichment":{"status":"complete","summary":"SP Page Builder for Joomla contains an unauthenticated arbitrary file upload vulnerability allowing remote attackers to upload malicious files, including PHP scripts, directly to the server. This leads to remote code execution as the uploaded PHP files can be accessed and executed by the web server.","mitigation":"Immediately update SP Page Builder to the latest patched version or disable the component until a patch is available. If updates are not possible, restrict access to the component through web server configuration or firewall rules.","confidence":"high","poc_url":null,"patch_commit_url":null},"cwes":[{"id":"CWE-434","name":"Unrestricted File Upload"}],"references":[{"url":"https://www.joomshaper.com/page-builder","tags":["Product"]},{"url":"https://extensions.joomla.org/extension/sp-page-builder/","tags":["Product"]},{"url":"https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/","tags":["Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48908","tags":["US Government Resource"]},{"url":"https://www.joomshaper.com/forum/question/45152","tags":["Issue Tracking"]}]},"attribution":{"source":"dbcve.org","license":"CC-BY-4.0","terms":"Base CVE data derived from NVD (public domain). dbcve.org enrichment is CC-BY-4.0 — attribution to dbcve.org required.","docs":"https://dbcve.org/api"}}