1.
yeswehack.com | vulnerability | Critical | [Actively exploited] | | original ↗ | #active-exploitation | #rce | #public-poc | #access-control
YesWeHack's analysis of CVE-2026-48907, a CVSS 10.0 unauthenticated RCE in the Joomla Content Editor: profile import abuse drops a PHP webshell; fixed in 2.9.99.5 with hardening in 2.9.99.6.
Skip to content