A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.joomlacontenteditor.net/ |
|
History
Fri, 05 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Joomlacontenteditor.net
Joomlacontenteditor.net joomla Content Editor (jce) Extension For Joomla |
|
| Vendors & Products |
Joomlacontenteditor.net
Joomlacontenteditor.net joomla Content Editor (jce) Extension For Joomla |
Fri, 05 Jun 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution. | |
| Title | Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5 | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Joomla
Published: 2026-06-05T07:31:30.257Z
Updated: 2026-06-05T07:31:30.257Z
Reserved: 2026-05-26T10:06:17.657Z
Link: CVE-2026-48907
No data.
Status : Received
Published: 2026-06-05T08:16:30.797
Modified: 2026-06-05T08:16:30.797
Link: CVE-2026-48907
No data.