← Back to browse · API

CVE-2026-48909

Severity
CRITICAL
CVSS
9.5
EPSS
0.07638
Risk score
40.67
CISA KEV
No
PoC
Yes
Published
2026-06-20
Modified
2026-06-23
First seen
2026-08-07
Aliases
EUVD-2026-38108, GHSA-GF8C-XMWJ-WHRH
Products
joomshaper.net:SP LMS extension for Joomla 1.0.0-4.1.3
Sources
packetstorm e42a2d3d450a1444fe7f9bd5|CVE-2026-48909
euvd EUVD-2026-38108
packetstorm 3ba6dd0930285a385303c680|CVE-2026-48909

Description

SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server.

References