CVE-2026-48908 · High · CISA KEV

JoomShaper SP Page Builder: Unrestricted File Upload Leads to Remote Code Execution

Threat Engine Auto-Feed · data current as of 2026-07-07

A critical unrestricted file upload vulnerability in JoomShaper SP Page Builder allows unauthenticated attackers to upload arbitrary files, including malicious PHP code. This flaw, actively exploited in the wild and listed in CISA KEV, enables remote code execution on affected systems. Organizations using this product should prioritize immediate patching.

  • CVSS:
  • EPSS percentile: 0.52274
  • Exploitation pressure: 56/100 (High)

Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 52th percentile. Threat × Vulnerability from public signals — impact depends on your environment.

Weakness —

This vulnerability involves a system allowing users to upload files without properly checking if the file type is safe or if the file itself contains dangerous content. Attackers can exploit this by uploading files that are not intended to be executable, such as PHP scripts, which the server then runs, giving them control.

Who's at risk

Exposure: unknown · Auth: unknown · unknown

Enterprise profiles most at risk

  • Organizations using JoomShaper SP Page Builder, especially those in financial services and technology sectors due to observed adversary targeting.
  • Any enterprise with web applications allowing file uploads without robust validation.

Misconfigurations that escalate it

  • Web servers configured to execute uploaded files from user-controlled directories.
  • Lack of strict file type validation and content-sniffing on file upload functionalities.

High-impact scenarios

  • Remote Code Execution (RCE) on the web server, leading to full system compromise.
  • Website defacement, data theft, or installation of backdoors and ransomware.
  • Lateral movement within the network from the compromised web server.

Likely adversaries

  • FIN7 — Financial services (Assessed)
  • LockBit affiliates — Financial services (Assessed)
  • APT38 (Lazarus) — Financial services (Assessed)
  • APT29 (Cozy Bear) — Technology (Assessed)
  • Scattered Spider — Technology (Assessed)

What to do (defensive)

Detect

  • Monitor web server logs for suspicious file uploads, especially for unusual file types (e.g., .php, .phtml) in upload directories.
  • Look for unexpected file creations or modifications in web root directories.
  • Implement Web Application Firewall (WAF) rules to detect and block malicious file upload attempts.

Contain

  • Isolate affected JoomShaper SP Page Builder instances from the network.
  • Review and restrict permissions on web server upload directories to prevent execution of arbitrary files.

Patch

  • Apply the latest security patches and updates for JoomShaper SP Page Builder immediately.

Frontier verdict — High

This is a high-priority vulnerability due to active exploitation (CISA KEV) and the potential for unauthenticated remote code execution.

For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.