Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
Title source: cnaExploitation Summary
CVE-2026-48907 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 16, 2026. EIP tracks 22 public exploits from researchers including ChiefYoru, amnsecurity, dyeat. A Nuclei detection template is also available.
AI-analyzed exploit summary This PoC exploits an unauthenticated arbitrary file upload vulnerability in the Joomla JCE extension (CVE-2026-48907) to achieve remote code execution by uploading a PHP webshell. The exploit includes CSRF token extraction, mass exploitation capabilities, and thread-safe target processing.
Description
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
Exploits (22)
This PoC exploits an unauthenticated arbitrary file upload vulnerability in the Joomla JCE extension (CVE-2026-48907) to achieve remote code execution by uploading a PHP webshell. The exploit includes CSRF token extraction, mass exploitation capabilities, and thread-safe target processing.
This repository contains a functional Python exploit for CVE-2026-48907, an unauthenticated remote code execution vulnerability in Joomla's JCE Editor. The exploit creates a malicious editor profile allowing PHP file uploads, then uploads a web shell for command execution.
This repository contains a functional exploit for CVE-2026-48907, an unauthenticated RCE vulnerability in Joomla Content Editor (JCE). The exploit uploads a malicious PHP file to the tmp/ directory via a CSRF-protected profile import feature and executes it.
This repository contains no actual exploit code or technical analysis for CVE-2026-48907. It only lists external GitHub repositories and an encrypted backup link, with no in-depth vulnerability details or functional PoC.
This exploit targets an unauthenticated remote code execution vulnerability in the JCE (Joomla Content Editor) extension for Joomla (< 2.9.99.5). It abuses the profile import functionality to upload arbitrary PHP files and achieve RCE via crafted XML payloads.
This repository contains a functional exploit for CVE-2026-48907, targeting Joomla's JCE component to achieve unauthenticated remote code execution (RCE) via profile import and file upload manipulation.
This repository contains a functional exploit for CVE-2026-48907, an unauthenticated RCE vulnerability in Joomla JCE. It includes a Dockerized lab environment, a PHP webshell, and step-by-step instructions to exploit the vulnerability via unauthenticated file upload.
This repository contains a functional exploit for CVE-2026-48907, an unauthenticated RCE vulnerability in Joomla JCE. The exploit automates CSRF token extraction, malicious profile upload, and command execution via a PHP webshell.
This repository contains a functional Python-based scanner and exploit for CVE-2026-48907, targeting Joomla! JCE Editor versions below 2.9.99.5. The exploit verifies unauthenticated RCE by uploading a harmless PHP payload and confirming execution via a math-based verification mechanism.
This repository contains a functional Python-based exploit for CVE-2026-48907, targeting an unauthenticated RCE vulnerability in the Joomla JCE Editor. The exploit chain includes fingerprinting, CSRF token extraction, malicious profile import, and PHP payload upload.
This repository contains a scanner for CVE-2026-48907, an unauthenticated RCE vulnerability in Joomla Content Editor (JCE) ≤ 2.9.99.4. The scanner detects the vulnerability by checking for missing authentication on the profiles.import endpoint and other conditions, but does not include exploit code for RCE.
This repository contains a Python-based scanner for detecting CVE-2026-48907, an unauthenticated RCE vulnerability in Joomla! JCE Editor versions below 2.9.99.5. The tool performs fingerprinting, WAF detection, and a math-verification payload test to confirm vulnerability presence.
This repository contains a functional exploit for CVE-2026-48907, targeting an unauthenticated arbitrary file upload vulnerability in Joomla! JCE extension versions below 2.9.99.5. The exploit demonstrates remote code execution by uploading a custom PHP file via a CSRF-protected endpoint, bypassing authentication.
This repository contains a functional exploit for CVE-2026-48907, targeting a vulnerability in JCE (Joomla Content Editor). The exploit includes methods for token extraction, file upload, and command execution via SSI (Server-Side Includes) and PHP shells.
This repository contains Sigma rules for detecting exploitation attempts and post-exploitation activity related to CVE-2026-48907, a Joomla JCE component vulnerability. It includes detection logic for suspicious POST requests, webshell access, and anomalous process execution, but no functional exploit code.
This repository contains Sigma rules for detecting exploitation attempts and post-exploitation artifacts related to CVE-2026-48907, a vulnerability in the Joomla JCE component. It includes detection logic for web server logs and auditd events, but does not contain functional exploit code.
This repository contains a functional Python exploit for CVE-2026-48907, an improper access control vulnerability in the JCE editor extension for Joomla. The exploit uploads a PHP payload (alfa.php) via a CSRF-protected endpoint and executes it to achieve remote code execution.
The repository contains multiple functional Python scripts that exploit CVE-2026-48907, an unauthenticated RCE vulnerability in Joomla's JCE (Joomla Content Editor) component. The exploits automate the process of detecting JCE, importing malicious profiles, and uploading PHP webshells via the JCE file browser plugin.
This repository contains a functional exploit for CVE-2026-48907, targeting an unauthenticated RCE vulnerability in Joomla's JCE (Joomla Content Editor) component. The exploit automates the process of detecting vulnerable installations, importing malicious profiles, and uploading PHP payloads to achieve remote code execution.
This repository provides a detailed technical analysis of CVE-2026-48907, an unauthenticated RCE vulnerability in JCE (Joomla Content Editor) caused by improper access control (CWE-284). It includes root cause analysis, exploitation flow, mitigation steps, and detection opportunities but does not contain actual exploit code.
This repository contains a functional exploit PoC for CVE-2026-48907, targeting a Joomla vulnerability. The exploit demonstrates arbitrary file upload and remote code execution by uploading a malicious PHP file to the tmp/ directory and executing it.
This repository contains a functional exploit for CVE-2026-48907, an unauthenticated RCE vulnerability in JCE Joomla. The exploit automates the process of uploading malicious PHP payloads via the JCE editor's file upload functionality and verifies RCE by executing arbitrary commands.
Nuclei Templates (1)
http.component:"Joomla"
app="Joomla"
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H