CVE-2026-48907

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

Scoring

Severity
CRITICAL
CVSS base score
10
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red
EPSS probability
78.10%
CISA KEV
Known exploited vulnerability
CWE
CWE-284
Published
2026-06-05
Last modified
2026-06-20

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs