CVE-2026-48907 (matched: php)

  • Thursday, 23rd July, 2026
  • 22:05pm

A security vulnerability has been found in the JCE Editor extension, an add-on for Joomla, a popular tool for building and managing websites. The flaw lets people who do not have an account or login for your Joomla site create their own editor profiles for the JCE extension. This access allows them to upload and run PHP code on your website. Being able to upload and run PHP code on a site is a serious risk, as it could let attackers steal data from your site and its visitors, alter or remove content from your public pages, or take complete control of your site and all information stored on it.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-48907

« Back