The CVE-2026-48908 vulnerability in JoomShaper SP Page Builder allows unrestricted upload of files with dangerous types, posing a critical risk with a CVSS score of 10. This vulnerability is known to be exploited in the wild and requires immediate attention. Affected product deployments should be identified in managed environments, and owners should be assigned for follow-up. The vulnerability allows for [truncated]
CVE-2026-48909 is a critical vulnerability in SP LMS (com_splms) versions before 4.1.4. The issue allows unauthenticated remote attackers to execute arbitrary code on the server due to deserialization of user-controlled cookie data without validation. With a CVSS score of 9.5, this vulnerability is considered critical. Organizations using affected versions of SP LMS should prioritize immediate remediation.