CVE-2026-48907 (matched: php)

  • Thursday, 23rd July, 2026
  • 16:05pm

A security vulnerability has been identified in the JCE editor extension, a tool many site owners use to edit content on Joomla websites. This flaw allows people who do not have valid login credentials for your site to create new custom profiles for the JCE editor. These unauthorized profiles can be used to upload and run harmful code on your website. This could let attackers modify your site’s public content, steal data from your site or your visitors, or take other unwanted actions linked to your hosting account.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-48907

« Back