๐Ÿ” CVE Alert

CVE-2026-48907

UNKNOWN 0.0

Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5

CVSS Score
0.0
EPSS Score
0.1%
EPSS Percentile
29th

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

CWE CWE-284
Vendor joomlacontenteditor.net
Product joomla content editor (jce) extension for joomla
Published Jun 5, 2026
Last Updated Jun 5, 2026
Stay Ahead of the Next One

Get instant alerts for joomlacontenteditor.net joomla content editor (jce) extension for joomla

Be the first to know when new unknown vulnerabilities affecting joomlacontenteditor.net joomla content editor (jce) extension for joomla are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

joomlacontenteditor.net / Joomla Content Editor (JCE) extension for Joomla
1.0.0-2.9.99.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
joomlacontenteditor.net: https://www.joomlacontenteditor.net/

Credits

David Jardin Uwe Flottemesch