VYPR
Critical severityCISA KEVNVD Advisory· Published Jun 5, 2026· Updated Jun 16, 2026

CVE-2026-48907

CVE-2026-48907

Description

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

2

News mentions

10