Unauthenticated RCE PoC for CVE-2026-48908 — SP Page Builder for Joomla (≤ 6.6.1): arbitrary file upload via asset.uploadCustomIcon. Self-cleaning, token-guarded. Authorized testing only.
proof-of-concept exploit joomla penetration-testing poc rce vulnerability web-security unauthenticated sp-page-builder remote-code-execution arbitrary-file-upload sppagebuilder cve-2026-48908
-
Updated
Jun 23, 2026 - Python