GHSA-c3f5-4g7f-qjqjCriticalCVSS 9.8
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles...
🔗 CVE IDs covered (1)
📋 Description
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-48907
- https://www.joomlacontenteditor.net
- https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48907
- https://github.com/advisories/GHSA-c3f5-4g7f-qjqj