<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — JoomShaper</title><description>Actively exploited vulnerabilities affecting JoomShaper products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/joomshaper.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-48908 — JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-48908</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-48908</guid><description>This vulnerability in JoomShaper&apos;s SP Page Builder allows anyone on the internet — no login required — to upload arbitrary files, including PHP scripts, to an affected server. Once a malicious PHP file is uploaded and executed, an attacker effectively gains remote code execution on the web server. This makes it a critical risk for any organization running this Joomla plugin, as full server compromise is achievable without any authentication barrier.</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><category>JoomShaper</category><category>SP Page Builder</category></item></channel></rss>