> cat /dev/github | grep security-tools
discovered 03 Aug 2026

CVE-2026-48909

Python ★ 23 via github-topic
→ View on GitHub
The CVE-2026-48909 tool identifies and exploits a critical Remote Code Execution vulnerability via PHP Object Injection in the JoomShaper SP LMS extension for Joomla versions ≤ 4.1.3. Notable features include a proof of concept script for detecting the vulnerability and an exploit script that allows an attacker to write PHP code to the server, requiring no authentication. The tool also details the underlying mechanics of the vulnerability and provides mitigation advice for affected systems.