Pre-Auth RCE in Joomla Content Editor: Profile Import to PHP Execution (CVE-2026-48907)
CVE-2026-48907 is a critical unauthenticated remote code execution flaw in the Joomla Content Editor (JCE), the most widely installed editor extension for Joomla.