Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-48907

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.047
EPSS Ranking 90.6%
CVSS Severity
CVSS v3 Score 9.8
Proposed Action
Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
Ransomware Campaign
Unknown
Products affected by CVE-2026-48907


Contact Us

Shodan ® - All rights reserved