CVE-2026-48909 is a deserialization vulnerability in JoomShaper SP LMS (com_splms) versions prior to 4.1.4. The component reads user-controlled cookie data, base64-decodes it, and passes the result directly to PHP unserialize() without validation in the cart handling logic. This creates a PHP Object Injection condition reachable without authentication. The vulnerable behavior is associated with processing of the lmsOrders cookie in the component's cart model. In affected environments, attacker-supplied serialized objects can be instantiated during deserialization. Where a suitable gadget chain is present, including the referenced Joomla FormattedtextLogger chain in Joomla versions earlier than 5.2.2, the flaw can be escalated from object injection to unauthenticated remote code execution on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This six-file Python/PHP repository is an operational Joomla exploitation suite. CVE-2026-Joomla-Suite.py is the command-line entry point: it accepts one target or a target list, can fingerprint installed extensions, supports concurrent scanning, optional proxying and JSON output, and invokes the modules in joomla_exploits.py. It loads payloads/x7-panel.php and attempts the listed extension-specific CVE modules in sequence or a module selected with --cve. Successful deployments are logged locally in panels_joomla.txt and scan_joomla_live.log. The suite claims seven unauthenticated extension paths and includes an additional credential-dependent CVE-2026-73373/com_media path in code. The PHP payload is a functional web shell rather than a benign proof-of-concept: it exposes unauthenticated command execution, filesystem reconnaissance, and arbitrary file-writing/upload features. The only Python dependency is requests; winrarzips_brand.py provides presentation/banner code. CVE and affected-version claims are repository assertions; only the SP LMS Joomla <5.2.2 condition is explicitly stated in the supplied content.
Repository is a small standalone Python exploit project with 4 files: LICENSE, README.md, requirements.txt, and a single main script exploit.py. The code is not part of a known exploitation framework. The README and script both describe a proof-of-concept/assessment tool for CVE-2026-48909, targeting Joomla sites running the SP LMS extension. The exploit is clearly intended for network/web exploitation and goes beyond simple detection. The main capabilities visible from exploit.py and the README are: unauthenticated exploitation, writable-path discovery, deployment of PHP webshells, arbitrary command execution, interactive shell support, reverse shell support, optional cleanup, logging/report generation, proxy support, user-agent rotation, and multi-target threaded scanning. The embedded payload set includes several PHP shell variants: GET/POST command shells, a header-driven stealth shell using HTTP_X_CMD, a base64 eval shell, a fuller shell with output formatting, a reverse shell using fsockopen plus /bin/sh, and a blind shell variant. This makes the repository operational rather than a mere detector. Fingerprintable target artifacts are primarily filesystem paths used as candidate drop locations for the webshell, including Joomla-related directories such as /components/com_splms/, /administrator/components/com_splms/, /modules/mod_splms/, /modules/mod_sp_lms/, /media/com_splms/assets/, and generic writable locations like /tmp/x.php, /cache/x.php, and /images/x.php. The payloads also expose recognizable command channels via parameters cmd, c, h, and p, plus the custom HTTP header HTTP_X_CMD. The reverse shell payload invokes /bin/sh on the target. The repository structure is straightforward: exploit.py is the entry point and contains configuration, payload definitions, logging, exploitation flow, reporting, and interactive shell logic; requirements.txt lists requests and urllib3 dependencies; README.md documents usage, options, and claimed features. Based on the available code and documentation, this is a real exploit tool for remote code execution against vulnerable Joomla SP LMS deployments, not just a README or detection-only script.
Repository contains two Python scripts and supporting documentation for CVE-2026-48909, a PHP object injection flaw in JoomShaper SP LMS (com_splms). The structure is simple: one detection script (CVE-2026-48909.py), one exploitation script (CVE-2026-48909_exploit.py), plus README, license, and .gitignore. The detection script is not an exploit by itself; it probes the Joomla SP LMS cart endpoint /index.php?option=com_splms&view=cart using the lmsOrders cookie with benign and serialized test values, then infers vulnerability from HTTP status changes, PHP error text, response size differences, or timing anomalies. The exploit script is a real unauthenticated web attack that targets the same endpoint and abuses unsafe unserialize(base64_decode(cookie)) behavior. It constructs a serialized Joomla FormattedtextLogger gadget chain, base64-encodes it, and iterates padding to avoid Joomla cookie filtering of '/', '+', and '='. On success, the gadget writes PHP code to an attacker-specified absolute server path, creating a webshell. The script then requests the written file once to trigger overwrite logic and again with ?c=id to verify command execution. Main capabilities are vulnerability detection, payload generation that is filter-safe, arbitrary file write via gadget chain, webshell deployment, and remote command execution through a GET parameter. No hardcoded external C2 or third-party network infrastructure is present; all network interaction is directed at the supplied target URL and the derived shell URL. Overall, this is a focused Python PoC/operational exploit repository for unauthenticated RCE against vulnerable Joomla SP LMS installations, with the exploit dependent on both SP LMS <= 4.1.3 and Joomla versions prior to 5.2.2 for the public gadget chain to succeed.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability affecting Joomla SP LMS versions 4.1.3 and earlier, described in the content as an unauthenticated PHP object injection leading to RCE.
A PHP Object Injection vulnerability in JoomShaper SP LMS (com_splms) <= 4.1.3 caused by unsafe unserialize() of the lmsOrders cookie. It can be detected via an HTTP response side channel and, when combined with a Joomla gadget chain, can lead to unauthenticated remote code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.