CVE-2026-48907
KEV Critical · CVSS 9.8- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- Listed
- 2026-06-16
- Class
- oss containerizable
- CWE-284
Description
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
References
Status: profiled · ingested 2026-07-23T12:00:18.000Z