Dear JoomShaper team,
I am a long-standing SP Page Builder customer running several Joomla websites for a meditation centre and a small adventure-travel business in the Himalayas. I am writing to make you aware of the serious, real-world impact that the critical vulnerability CVE-2026-48908 (the unauthenticated arbitrary file upload / RCE via asset.uploadCustomIcon) had on my websites, and to ask you to improve how you communicate critical security issues to your customers.
Through this vulnerability, attackers uploaded multiple PHP web shells into the SP Page Builder icon directories across more than one of my sites. Using that access they:
defaced my main site (os------ga.com),
injected hidden casino/betting spam links into pages,
and — most damagingly — used the foothold to submit Google Search Console removal requests that hid my entire website from Google for roughly three weeks.
The result was a near-total loss of search traffic and enquiries during that period, significant financial and reputational harm to a charitable organisation, and close to three weeks of intensive, stressful recovery work. This was a CVSS 10.0 vulnerability in your flagship product, exploitable by anyone with no authentication whatsoever — the most severe class of flaw a web application can have.
I acknowledge that you released a fix in version 6.6.2. My concern is this: I received no proactive notification from you that a critical, actively-exploited vulnerability had been patched and that I needed to update urgently. I only learned the root cause after my hosting provider's forensic analysis, well after the damage was done. For a vulnerability that CISA added to its Known Exploited Vulnerabilities catalogue, silent publication of a patch is not enough — by the time customers discover it on their own, they have often already been breached, as I was.
I would therefore urge you to:
Proactively email all license holders immediately whenever a critical (high/critical severity) security fix is released, with a clear "update now" instruction — not rely on customers noticing a version bump.
Consider an in-dashboard security alert for critical updates, distinct from routine feature updates.
Acknowledge the impact this incident has had on affected customers.
I still value SP Page Builder and intend to keep using it — which is precisely why I am taking the time to write constructively rather than simply leaving. I would appreciate a response acknowledging these points and outlining what you will do to notify customers of critical vulnerabilities in future.
Yours sincerely,
Rahi