What happened
Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
Affected versions
Joomla Content Editor: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 52630Joomla 2.9.99.4 - Unauthenticated Remote Code ExecutionJared Brits2026-08-10VerifiedExploit-DB 52645Joomla JCE_2.9.15 - Remote Code ExecutionJared Brits2026-08-17VerifiedCVE-Intel · K3ysTr0K3R/CVE-2026-48907CVE-2026-48907 – Joomla JCE Unauthenticated Remote Code Execution (RCE)RCEPythonAwaiting Analysis★ 3⑂ 1EPSS 78.10%Code indexedUpdated 26 Aug 2026Tags: cve-2026-48907, exploit, joomla, joomla-rce, poc, proof-of-concept, rceK3ysTr0K3R2026-06-29CandidateCVE-Intel · gh1mau/masta-cve-2026-48907cve-2026-48907 scannerExploitPythonAwaiting Analysis★ 58⑂ 11EPSS 78.10%Code indexedUpdated 26 Aug 2026gh1mau2026-06-27CandidateCVE-Intel · ksotaria1337/-CVE-2026-48907-ExploitPythonAwaiting Analysis★ 0⑂ 0EPSS 78.10%Code indexedUpdated 26 Aug 2026ksotaria13372026-08-26CandidateCVE-Intel · CerberusMrXi/JCEzploit-CVE-2026-48907JCEzploit is a powerful, fully-automated RCE exploit for Joomla JCE (CVE-2026-48907) featuring interactive shell, batch command execution, file download capability, and proxy support. Built with Python & Rich for penetration testers. Ethical use only. By Sudeepa Wanigarathna.RCEPythonAwaiting Analysis★ 0⑂ 0EPSS 78.10%Code indexedUpdated 25 Aug 2026CerberusMrXi2026-08-21CandidateCVE-Intel · 0xgh057r3c0n/CVE-2026-48907CVE-2025-48907 - Unauthenticated RCE exploit for Joomla JCE < 2.9.99.5RCEPythonAwaiting Analysis★ 3⑂ 2EPSS 78.10%Code indexedUpdated 21 Aug 20260xgh057r3c0n2026-06-22CandidateCVE-Intel · sec0x/CVE-2026-48907ExploitPythonAwaiting Analysis★ 1⑂ 0EPSS 78.10%Code indexedUpdated 5 Aug 2026sec0x2026-06-22CandidateCVE-Intel · pssec-io/CVE-2026-48907POC for CVE-2026-48907PoCPHPAwaiting Analysis★ 1⑂ 0EPSS 78.10%Code indexedUpdated 23 Jul 2026Tags: cve-2026-48907, joomla, poc, proof-of-concept, pssec, pssec-iopssec-io2026-06-30CandidateCVE-Intel · ChiefYoru/CVE-2026-48907_PoCUnauthenticated Remote Code Execution (RCE) vulnerability in the JCE (Joomla Content Editor) extension for JoomlaRCEPythonAwaiting Analysis★ 1⑂ 0EPSS 78.10%Code indexedUpdated 19 Jul 2026ChiefYoru2026-07-19Candidatebayu06802/CVE-2026-48907Python & template nuclei★ 0bayu068022026-07-04VerifiedNoXiVaR/CVE-2026-48907CVE-2026-48907 PoC★ 0NoXiVaR2026-07-01VerifiedAlmavj/Joomla_CVE_2026_48907cve-2026-48907 scanner★ 0Almavj2026-06-29Candidatexitexploiter96-dot/CVE-2026-48907-★ 0xitexploiter96-dot2026-06-29VerifiedSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.