CVE-2026-48907
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
CVSS Score
0.0
EPSS Score
6.9%
EPSS Percentile
93th
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
| CWE | CWE-284 |
| Vendor | joomlacontenteditor.net |
| Product | joomla content editor (jce) extension for joomla |
| Published | Jun 5, 2026 |
| Last Updated | Jun 20, 2026 |
โ ๏ธ Actively Exploited โ Act Now
Get instant alerts for joomlacontenteditor.net joomla content editor (jce) extension for joomla
This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2026-48907.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
joomlacontenteditor.net / Joomla Content Editor (JCE) extension for Joomla
1.0.0-2.9.99.4
References
Credits
David Jardin Uwe Flottemesch