قاعدة الثغرات (CVE)
CVE-2026-48907
رفع وتنفيذ PHP دون مصادقة في Joomla Content Editor (JCE)
حرجةمُستغلة فعليًاKEVالتصحيح متوفر: غير متوفر بعد
تحكم وصول غير سليم يسمح لمستخدمين غير مصادَقين بإنشاء ملفات تعريف محرر جديدة ورفع شفرة PHP وتنفيذها على مواقع Joomla.
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
المنتجات المتأثرة
| Product | الإصدارات المتأثرة | تم الإصلاح في |
|---|---|---|
| Joomla Content Editor | — | — |
التغطية على سيبرانا
—