EUVD-2026-38110
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 6 Jul 2026. Evidence sources: cisa_kev, eukev_kev.
- ENISA score
- 10.0 · CVSS 4.0
- Advisory evidence
- No linked advisory details stored yet
