A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.joomlacontenteditor.net/ |
|
History
Fri, 05 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Joomlacontenteditor.net
Joomlacontenteditor.net joomla Content Editor (jce) Extension For Joomla |
|
| Vendors & Products |
Joomlacontenteditor.net
Joomlacontenteditor.net joomla Content Editor (jce) Extension For Joomla |
Fri, 05 Jun 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution. | |
| Title | Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5 | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-06-05T07:31:30.257Z
Reserved: 2026-05-26T10:06:17.657Z
Link: CVE-2026-48907
No data.
Status : Received
Published: 2026-06-05T08:16:30.797
Modified: 2026-06-05T08:16:30.797
Link: CVE-2026-48907
No data.
OpenCVE Enrichment
Updated: 2026-06-05T10:07:00Z
Weaknesses