Clandestine[verified]@akaclandestinePoC
The GitHub repository hosts a proof‑of‑concept exploit for CVE‑2026‑48909, detailing the vulnerability and providing execution code, but it does not indicate active exploitation or mention patches.
dbugs[verified]@ptdbugsPoC
An active proof‑of‑concept exploit for CVE‑2026‑48909 targeting the SP LMS Joomla extension is publicly available, confirming its vulnerability to remote code execution via object injection.
DFIR Radar[verified]@DFIR_RadarDisclosure
The post announces the discovery of CVE-2026-48909, detailing how a PHP object injection in JoomShaper SP LMS allows webshell creation and RCE on Joomla sites.
ADK Cyber[verified]@ADKCyberDisclosure
The tweet announces CVE-2026-48909, a high‑severity RCE vulnerability affecting SP LMS on Joomla prior to 4.1.4, and urges sites to apply updates promptly.
Dark Web Informer@DarkWebInformerPoC
The tweet announces CVE-2026-48909 with a high CVSS score, provides a direct PoC link that demonstrates RCE, but offers no evidence of active exploitation or remediation steps.
ExploitGrid@exploitgridExploit
The post catalogs several CVEs with publicly available exploits, noting that at least one is actively being used in the wild, but offers no patch or mitigation information.
pdnuclei-bot@pdnuclei_botDisclosure
The tweet announces CVE‑2026‑48909, a critical remote code execution flaw affecting Joomla SP LMS versions 4.1.3 and earlier, and directs readers to a ProjectDiscovery library page for further details.
Red Secure Tech Ltd.@redsecuretechPatch
The post warns of a Joomla SP LMS PHP object injection flaw (CVE-2026-48909) that allows RCE via the lmsOrders cookie and recommends updating to version 4.1.4 or Joomla 5.2.2 for remediation.