CVE-2026-48907 (matched: php)

  • Saturday, 25th July, 2026
  • 22:04pm

A security flaw has been identified in the JCE editor extension, a widely used tool for editing content on Joomla-powered websites. This vulnerability allows anyone without a valid login to your site to create new, unauthorized editor profiles on their own.

Once an attacker creates one of these unapproved profiles, they can upload and run custom code on your website. This could let them alter your site’s content, steal personal or business data from you or your visitors, or abuse your hosting resources for malicious purposes like sending spam or attacking other sites.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-48907

« Back