Joomla extensions hit by two unauthenticated file upload flaws
Two Joomla extensions carry unauthenticated arbitrary file upload vulnerabilities: CVE-2026-48907 in JCE Editor and CVE-2026-48908 in SP Page Builder. Both are rated high, and FortiGuard Labs observed active exploitation of CVE-2026-48908 after public disclosure.
- CVE-2026-48907 affects JCE Editor, CVE-2026-48908 affects SP Page Builder
- Vulnerable endpoints: profiles.import and asset.uploadCustomIcon
- Uploading a PHP file leads to remote code execution on the server
- FortiGuard reports active exploitation of CVE-2026-48908
Read next
Security