CVE-2026-48907 in the Joomla JCE plugin lets unauthenticated attackers drop PHP web shells with a single crafted request.
By Diogo Cavazzini, Product & Marketing Director, PaperLess Europe* 1000+ Implementations | Sage Intacct Certified Partner ...