Critical Vulnerabilities in Joomla CMS Extensions

Three Joomla CMS extensions—Joomla Content Editor (JCE), SP Page Builder, and Page Builder CK—have been found to contain critical vulnerabilities: CVE-2026-48907 (CVSS 10.0) in JCE versions below 2.9.99.5, allowing unauthenticated attackers to create new editor profiles and execute arbitrary PHP code, potentially taking full control of the server. CVE-2026-48908 (CVSS 10.0) in SP Page Builder versions below 6.6.2, permits arbitrary file uploads leading to remote code execution. CVE-2026-56290 (CVSS 9.8) in Page Builder CK versions below 3.6.0 also allows arbitrary file uploads resulting in remote code execution. Immediate updates are required as these vulnerabilities are actively exploited in cyberattacks. More information is available at the provided links.

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source