PT-2026-46908 · Joomlacontenteditor.Net · Joomla Content Editor (Jce) Extension For Joomla

David Jardin

+1

·

Published

2026-06-05

·

Updated

2026-06-05

·

CVE-2026-48907

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-48907

Affected Products

Joomla Content Editor (Jce) Extension For Joomla