Critical CVE-2026-48908, CVE-2026-48907, CVE-2026-56290, CVE-2026-56291, CVE-2026-48939 — Five popular Joomla extensions had unauthenticated file-upload bugs in mid-2026 that give remote code execution, and all five are on CISA's exploited list. Fixed versions and how to clean a hacked Joomla site.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: If your website runs on Joomla, check your extensions now. Five widely used ones (SP Page Builder, JCE editor, Page Builder CK, Balbooa Forms and iCagenda) let anonymous visitors upload PHP files and take over the site. All are rated CVSS 10 and are being exploited. Update each extension, then check for web shells.
| CVE-2026-48908 | SP Page Builder (JoomShaper) < 6.6.2: unauthenticated file upload → RCE. KEV 2026-07-07 |
|---|---|
| CVE-2026-48907 | JCE editor < 2.9.99.5: unauthenticated users can create editor profiles → PHP upload. KEV 2026-06-16 |
| CVE-2026-56290 | Page Builder CK (joomlack.fr) ≤ 3.6.0: unauthenticated file upload → RCE. KEV 2026-07-07 |
| CVE-2026-56291 | Balbooa Forms < 2.4.1: unauthenticated file upload → RCE. KEV 2026-07-10 |
| CVE-2026-48939 | iCagenda 3.2.1–4.0.7: attachment upload → RCE. Fixed 4.0.8 / 3.9.15. KEV 2026-07-10 |
| Severity | All CVSS 4.0: 10 |
Joomla core wasn’t the problem this time; its extensions were. In June and July 2026, five popular third-party extensions turned out to accept file uploads from anonymous visitors without checking file type, so an attacker could upload a .php file and then run it by visiting its URL. That’s full control of the website, and usually of the database and any other sites on the same account.
| Extension | Vulnerable | Update to |
|---|---|---|
| SP Page Builder (JoomShaper) | 1.0.0–6.6.1 | 6.6.2+ |
| JCE – Joomla Content Editor | 1.0.0–2.9.99.4 | 2.9.99.5+ (JCE also published a free patch for older sites) |
| Page Builder CK (joomlack.fr) | 1.0–3.6.0 | a release newer than 3.6.0 |
| Balbooa Forms | 1.0–2.4.0 | 2.4.1+ |
| iCagenda | 3.2.1–4.0.7 | 4.0.8+ (or 3.9.15 on the 3.x line) |
In the Joomla administrator: System → Manage → Extensions, search for each name and compare the version. Or System → Update → Extensions to see which have updates waiting.
find images/ media/ tmp/ -name '*.php' -o -name '*.phtml' 2>/dev/null
find . -name '*.php' -newer configuration.php -mtime -120 | head -50option=com_sppagebuilder, com_jce, com_pagebuilderck, com_baforms, com_icagenda) followed by GET requests to new files.configuration.php is stolen: change it, all admin passwords, and FTP/hosting passwords. Then restore clean files from before the compromise or reinstall Joomla and extensions fresh..htaccess in images/ with <FilesMatch "\.(php|phtml|phar)$"> Require all denied </FilesMatch>.Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.