CVE-2026-48907 (matched: php)

  • Saturday, 25th July, 2026
  • 16:05pm

There is a security flaw in the JCE editor extension, a tool commonly used with the Joomla website building platform. This issue allows people who do not have login access to your Joomla site to create new editor profiles, which in turn lets them upload and run harmful PHP code on your website.

If you run a Joomla site that uses the JCE editor extension, this vulnerability could let attackers deface your site, steal visitor or site data, or gain unauthorized control over parts of your website.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-48907

« Back