CVE-2026-48907 (matched: php)

  • Sunday, 26th July, 2026
  • 04:03am

A security flaw has been found in the JCE editor extension, a common add-on for websites built with the Joomla content management system. If your Joomla site uses this extension, this vulnerability allows people who do not have authorized login access to your site’s admin panel to create new editor user profiles without permission.

Attackers can exploit this issue to upload and execute custom PHP code on your site. PHP code powers most of the core functions of Joomla sites, so this level of access could allow unauthorized users to alter your site’s content, settings, or behavior without your knowledge.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-48907

« Back