Dossier
Joomla JCE
Coverage of Joomla JCE in the Nexus archive.
- CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
CISA added a maximum-severity vulnerability in Joomla JCE to its KEV catalog, citing active exploitation. The flaw, CVE-2026-48907 with a CVSS score of 10.0, involves improper access control allowing arbitrary PHP code execution.