Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

Joomla Sites Under Attack: 5 Exploited Extension Bugs (SP Page Builder, JCE, Page Builder CK, Balbooa Forms, iCagenda)

Critical CVE-2026-48908, CVE-2026-48907, CVE-2026-56290, CVE-2026-56291, CVE-2026-48939 — Five popular Joomla extensions had unauthenticated file-upload bugs in mid-2026 that give remote code execution, and all five are on CISA's exploited list. Fixed versions and how to clean a hacked Joomla site.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: If your website runs on Joomla, check your extensions now. Five widely used ones (SP Page Builder, JCE editor, Page Builder CK, Balbooa Forms and iCagenda) let anonymous visitors upload PHP files and take over the site. All are rated CVSS 10 and are being exploited. Update each extension, then check for web shells.

CVE-2026-48908SP Page Builder (JoomShaper) < 6.6.2: unauthenticated file upload → RCE. KEV 2026-07-07
CVE-2026-48907JCE editor < 2.9.99.5: unauthenticated users can create editor profiles → PHP upload. KEV 2026-06-16
CVE-2026-56290Page Builder CK (joomlack.fr) ≤ 3.6.0: unauthenticated file upload → RCE. KEV 2026-07-07
CVE-2026-56291Balbooa Forms < 2.4.1: unauthenticated file upload → RCE. KEV 2026-07-10
CVE-2026-48939iCagenda 3.2.1–4.0.7: attachment upload → RCE. Fixed 4.0.8 / 3.9.15. KEV 2026-07-10
SeverityAll CVSS 4.0: 10

What’s going on

Joomla core wasn’t the problem this time; its extensions were. In June and July 2026, five popular third-party extensions turned out to accept file uploads from anonymous visitors without checking file type, so an attacker could upload a .php file and then run it by visiting its URL. That’s full control of the website, and usually of the database and any other sites on the same account.

ExtensionVulnerableUpdate to
SP Page Builder (JoomShaper)1.0.0–6.6.16.6.2+
JCE – Joomla Content Editor1.0.0–2.9.99.42.9.99.5+ (JCE also published a free patch for older sites)
Page Builder CK (joomlack.fr)1.0–3.6.0a release newer than 3.6.0
Balbooa Forms1.0–2.4.02.4.1+
iCagenda3.2.1–4.0.74.0.8+ (or 3.9.15 on the 3.x line)

Am I affected?

In the Joomla administrator: System → Manage → Extensions, search for each name and compare the version. Or System → Update → Extensions to see which have updates waiting.

How to patch

  1. Back up the site files and database (Akeeba Backup or your host’s backup).
  2. Update the extensions from System → Update → Extensions. Paid extensions (SP Page Builder Pro, JCE Pro) need a valid download key entered under Update Sites.
  3. Update Joomla core while you’re there.
  4. If an extension is abandoned or you can’t update it, uninstall it.

Was my site hacked?

  • Look for PHP files where only images and documents should be:
    find images/ media/ tmp/ -name '*.php' -o -name '*.phtml' 2>/dev/null
    find . -name '*.php' -newer configuration.php -mtime -120 | head -50
  • Check Users → Manage for Super Users you didn’t create.
  • Look in the web server access log for POST requests to the extensions’ upload endpoints (option=com_sppagebuilder, com_jce, com_pagebuilderck, com_baforms, com_icagenda) followed by GET requests to new files.
  • If you find a web shell, assume the database password in configuration.php is stolen: change it, all admin passwords, and FTP/hosting passwords. Then restore clean files from before the compromise or reinstall Joomla and extensions fresh.

Prevent the next one

  • Block PHP execution in upload folders. On Apache, a .htaccess in images/ with <FilesMatch "\.(php|phtml|phar)$"> Require all denied </FilesMatch>.
  • Remove extensions you no longer use. Every installed extension is attack surface even if it’s unpublished.
  • Enable Joomla’s update notifications (and an uptime/file-change monitor) so you hear about these within days, not months.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories