Remote Code Execution Vulnerability in SP LMS by JoomShaper
CVE-2026-48909
9.5CRITICAL
What is CVE-2026-48909?
The SP LMS component (com_splms) version prior to 4.1.4 by JoomShaper contains a vulnerability that allows unauthenticated attackers to execute arbitrary code on the server. This issue arises from the unsanitized deserialization of user-controlled cookie data, posing significant security risks for installations that do not apply the necessary updates.
Affected Version(s)
SP LMS extension for Joomla 1.0.0-4.1.3
