CVE-2026-48907
CRITICAL
CVSS: 9.8
EPSS: 78.1%
VulnCheck KEV
PoC Available
Metasploit
ExploitDB
CWE-284
T1078
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
Published: 2026-06-05