CVE-2026-48907
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
- Published Jun 5, 2026
- CVSS 10.0 critical
- 16.2% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A Metasploit module exploits it
Affected software
In the news
- Aimy Captcha-Less Form Guard: The Anti-Bot Plugin That Hands Bots the Keys VulnCheck Blog ·
- Large-scale exploitation campaign targeting website content management systems (CMS) Australian Cyber Security Centre ·