chiprook
← Security
SecuritySeptember 30, 2026, 18:00

Joomla extensions hit by two unauthenticated file upload flaws

Two Joomla extensions carry unauthenticated arbitrary file upload vulnerabilities: CVE-2026-48907 in JCE Editor and CVE-2026-48908 in SP Page Builder. Both are rated high, and FortiGuard Labs observed active exploitation of CVE-2026-48908 after public disclosure.

Joomla extensions hit by two unauthenticated file upload flaws
#Joomla#JCEEditor#SPPageBuilder
Read next
Security

Microsoft Teams lets admins block custom file extensions

Security

LightLLM hit by two CVSS 9.8 unauthenticated RCE flaws

Business

Anthropic filing shows two customers drove nearly a quarter of $4.6B revenue

Business

Microsoft files to develop two-building campus outside Atlanta, Georgia