Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Security Flaw in JoomShaper SP Page Builder for Joomla

A serious security weakness has been found in the SP Page Builder software used with Joomla websites. This flaw allows attackers to upload harmful files without logging in, which can lead to malicious code running on the website. This vulnerability is actively being exploited, so immediate action is important.

08 July 2026

Reference: CVE-2026-48908

1. What is being reported?

The report describes a critical vulnerability in the SP Page Builder tool for Joomla. It allows anyone, even without an account, to upload files that can contain harmful PHP code. This means attackers can take control of the website by running their own code.

2. What this means in plain English

If your organisation uses Joomla with SP Page Builder, this flaw could let hackers break into your website, steal data, or cause damage. This is a high risk because no login is needed to exploit it. Small organisations with websites using this software are at risk if they do not apply fixes or protections.

3. Could this affect a small business?

Small businesses, charities, clubs, or trustees using Joomla websites with the SP Page Builder extension could be affected. If you do not use this software, or your website is not publicly accessible, you are likely not affected. Ask your IT provider to confirm.

4. What to do now

  • Check if your website uses Joomla with the SP Page Builder extension.
  • Contact your IT provider or software supplier immediately to apply any available security updates or mitigations.
  • If no fix is available, consider disabling or removing the SP Page Builder extension until a fix is provided.
  • Review your website’s exposure to the internet and follow any additional guidance from your IT support regarding this vulnerability.

5. Ask your IT provider

Can you confirm if our Joomla website uses SP Page Builder and, if so, have the latest security updates or mitigations for CVE-2026-48908 been applied?

6. Bottom line

If you use SP Page Builder on Joomla, act quickly to secure your website against this actively exploited vulnerability.

Information based on CISA KEV, NVD, and reputable security reporting.

Back to Vulnerability Briefs