๐Ÿ” CVE Alert

CVE-2026-48907

UNKNOWN 0.0 โš ๏ธ CISA KEV

Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5

CVSS Score
0.0
EPSS Score
6.9%
EPSS Percentile
93th

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

CWE CWE-284
Vendor joomlacontenteditor.net
Product joomla content editor (jce) extension for joomla
Published Jun 5, 2026
Last Updated Jun 20, 2026
โš ๏ธ Actively Exploited โ€” Act Now

Get instant alerts for joomlacontenteditor.net joomla content editor (jce) extension for joomla

This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2026-48907.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

joomlacontenteditor.net / Joomla Content Editor (JCE) extension for Joomla
1.0.0-2.9.99.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
joomlacontenteditor.net: https://www.joomlacontenteditor.net/ joomlacontenteditor.net: https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48907

Credits

David Jardin Uwe Flottemesch