[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":3,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":10,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":16,"all-banners":23,"vulnerability-29780":64},["Island",4],{"key":5,"params":6,"result":8},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":7},"{}",{"head":9},{},["Island",11],{"key":12,"params":13,"result":14},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":7},{"head":15},{},["Island",17],{"key":18,"params":19,"result":21},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":20},"{\"text-color\":\"gray\"}",{"head":22},{},[24,35,41,47,53,59],{"title":25,"slug":26,"text":27,"link":28,"external":29,"targets":30,"cta":32,"variant":33,"campaign_id":34},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[31],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":36,"slug":37,"text":38,"link":28,"external":29,"targets":39,"cta":32,"variant":33,"campaign_id":34},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[40],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":42,"slug":43,"text":44,"link":28,"external":29,"targets":45,"cta":32,"variant":33,"campaign_id":34},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[46],"\u002Ffeatures\u002Fpentest-reporting",{"title":48,"slug":49,"text":50,"link":28,"external":29,"targets":51,"cta":32,"variant":33,"campaign_id":34},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[52],"\u002Ffeatures\u002Fintegrations",{"title":54,"slug":55,"text":56,"link":28,"external":29,"targets":57,"cta":32,"variant":33,"campaign_id":34},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[58],"\u002Fexploit-helpers\u002Fsniper",{"title":60,"slug":34,"text":61,"link":28,"external":29,"targets":62,"cta":32,"variant":33,"campaign_id":34},"Compliance - Page Launch - Homepage","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.",[63],"\u002F",{"id":65,"detectable_with":66,"vuln_details":72,"vuln_id":97,"name":98,"published":99,"updated":99},29780,{"tool":67,"engine":70},{"id":68,"name":69},1,"Network Scanner",{"id":68,"name":71},"Sniper",{"id":65,"codename":73,"description":74,"severity":75,"risk_description":76,"public_description":77,"public_recommendation":78,"recommendation":79,"references":80,"cvssv3":85,"epss_score":86,"epss_percentile":87,"cve":88,"in_cisa_catalog":90,"date":91,"software_type":92,"vendor":93,"product":94,"ptt_exploit_capabilities":95},null,"We found that the target Joomla site is running the SP Page Builder extension, versions up to and including 6.6.1, which is vulnerable to an unauthenticated remote code execution. The vulnerability stems from a missing authentication check and a missing file-type restriction in the custom icon upload feature (com_sppagebuilder, task=asset.uploadCustomIcon): an unauthenticated attacker can submit a crafted icon-package ZIP archive, whose contents are extracted verbatim into a web-accessible directory (media\u002Fcom_sppagebuilder\u002Fassets\u002Ficonfont\u002F\u003Cname>\u002F) without any validation. By bundling a PHP file inside the archive, the attacker drops an executable script under the web root and can then execute arbitrary code by requesting the extracted file directly.","critical","The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network.","The SP Page Builder extension for Joomla, versions up to and including 6.6.1, is vulnerable to unauthenticated remote code execution due to an unrestricted file upload in its custom icon upload feature. An attacker can submit a crafted icon-package ZIP archive to the upload endpoint (com_sppagebuilder, task=asset.uploadCustomIcon), and the archive contents, including a bundled PHP file, are extracted into a web-accessible directory. Because the endpoint requires no authentication and performs insufficient validation, the extracted PHP file can be requested and executed remotely.","Update the SP Page Builder extension to version 6.6.2 or later.","We recommend updating the SP Page Builder extension to version 6.6.2 or later; if immediate update is not possible, disable or restrict the extension and ensure uploaded files are stored outside a web-executable location.",[81,82,83,84],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-48908","https:\u002F\u002Fmysites.guru\u002Fblog\u002Fsp-page-builder-zero-day-uploadcustomicon-rce\u002F","https:\u002F\u002Fgithub.com\u002Fpapageo75\u002FCVE-2026-48908-PoC","https:\u002F\u002Fwww.cisa.gov\u002Fknown-exploited-vulnerabilities-catalog",9.8,0.88512,0.9977,[89],"CVE-2026-48908",true,"2026-06-20T00:00:00Z","Joomla Extension","JoomShaper","SP Page Builder",[96],"RCE","NETSCAN-SNIPER-CVE-2026-48908","Joomla SP Page Builder - Remote Code Execution","2026-09-29T00:00:00Z"]