A critical security flaw has been identified in SP Page Builder, a popular tool used for building websites on the Joomla content management system. This vulnerability could allow malicious actors to take complete control of affected websites without needing any login credentials.
This is a serious issue because it involves “unauthenticated arbitrary file upload,” meaning an attacker can upload any kind of file to the server without logging in. Ultimately, this leads to “PHP code execution,” which allows them to run their own harmful code on the server. If exploited, an attacker could deface your website, steal sensitive data, or even use your server for other malicious activities.
It’s crucial for anyone using SP Page Builder for Joomla to understand this risk and take immediate action.
CVE Details
- Product: SP Page Builder for Joomla
- Published: June 20, 2026
- Severity: CRITICAL
- Status: Analyzed
Affected Products
This critical vulnerability affects all versions of SP Page Builder for Joomla. This means any website running SP Page Builder on a Joomla platform is potentially at risk until a patch or specific mitigation is applied.
Current Status
The vulnerability is currently in an “Analyzed” status, indicating that it has been publicly disclosed and its details are known.
Severity Level
With a CVSS score of 9.8, this vulnerability is classified as CRITICAL severity. A critical rating means that exploiting this flaw is straightforward and can lead to a complete compromise of the affected system. The potential impact is severe, allowing for full data control, system access, and denial of service.
Possible Solutions
While specific patch version details were not immediately available from the first official reference site, the nature of this vulnerability (arbitrary file upload leading to remote code execution) strongly suggests the following mitigation steps:
- Update Immediately: The most critical step is to update your SP Page Builder installation to the latest available version as soon as a security patch is released by the vendor (JoomShaper/Ollyo). Monitor the official JoomShaper website and your Joomla backend for update notifications.
- Web Application Firewall (WAF): Implement or enhance your Web Application Firewall rules to detect and block suspicious file uploads, especially PHP files, to sensitive directories.
- Restrict File Uploads: Configure your server and application settings to restrict file uploads to only necessary types and to secure, non-executable directories.
- Monitor for Suspicious Activity: Regularly monitor your Joomla website and server logs for any unusual file uploads, unexpected PHP script executions, or unauthorized access attempts.
- Backup Your Data: Always maintain recent backups of your website and database. In case of a successful exploit, a clean backup can significantly reduce recovery time and data loss.
Given the “zero-day” mention in one of the references, rapid patching is essential once it becomes available.
References
https://www.joomshaper.com/page-builder
https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/
https://www.joomshaper.com/forum/question/45152


