CVE-2026-48907
KEVCRITICAL 10.0EPSS 78.1%
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
- CVSS v4.0
- 10.0 CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 78.10% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2026-06-16
- Nuclei
- critical · CWE-284
- Published
- 2026-06-05
- Updated
- 2026-06-20
Proof-of-concept exploits (17)
- ywh-jfellus/CVE-2026-4890716★ · 2026-06-11
- 0xBlackash/CVE-2026-489073★ · 2026-06-12
- 0xgh057r3c0n/CVE-2026-489073★ · 2026-06-27
- K3ysTr0K3R/CVE-2026-489074★ · 2026-06-29
- HORKimhab/CVE-2026-489070★ · 2026-06-17
- NoXiVaR/CVE-2026-489070★ · 2026-07-01
- pssec-io/CVE-2026-489071★ · 2026-06-30
- wearehackers160/CVE-2026-489070★ · 2026-06-18
- 87achrafg-stack/CVE-2026-489070★ · 2026-06-13
- bayu06802/CVE-2026-489070★ · 2026-07-04
- sec0x/CVE-2026-489071★ · 2026-08-05
- ksotaria1337/-CVE-2026-48907-0★ · 2026-08-26
- CerberusMrXi/JCEzploit-CVE-2026-489070★ · 2026-08-21
- itsismarcos/COM_JCE_VANDA0★ · 2026-06-29
- ChiefYoru/CVE-2026-48907_PoC
- xitexploiter96-dot/CVE-2026-48907-
- ChrisSEC2014/joomla-content-editor--RCE