CVE-2026-48908: Joomla's Page Builder Handed Attackers the Keys, No Knock Required
A missing access check in SP Page Builder's icon-upload endpoint gave unauthenticated attackers direct RCE on every Joomla site running the extension. CVSS 10.0, actively exploited, patch available.