CVE-2026-48907
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
CVSS Score
0.0
EPSS Score
0.1%
EPSS Percentile
29th
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
| CWE | CWE-284 |
| Vendor | joomlacontenteditor.net |
| Product | joomla content editor (jce) extension for joomla |
| Published | Jun 5, 2026 |
| Last Updated | Jun 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for joomlacontenteditor.net joomla content editor (jce) extension for joomla
Be the first to know when new unknown vulnerabilities affecting joomlacontenteditor.net joomla content editor (jce) extension for joomla are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
joomlacontenteditor.net / Joomla Content Editor (JCE) extension for Joomla
1.0.0-2.9.99.4
References
Credits
David Jardin Uwe Flottemesch