Security Advisory

CVE-2026-48907

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-05 07:31:30
Last updated 2026-06-20 11:56:48
Assigner Joomla
CVSS score 10.0
State PUBLISHED

Description

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.