A security flaw, identified as CVE-2026-48907, exists in the JCE editor extension used by Joomla websites. This vulnerability allows people who do not have an account or login credentials for your Joomla site to create new editor profiles on the platform. Once created, these profiles let attackers upload and run harmful PHP code directly on your site. If this flaw is exploited, attackers could take full control of your Joomla site, steal sensitive business or visitor data, add malicious content, or use your site to target people who visit it.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-48907