Vulnerability intelligence
CVE-2026-3844 — Joomla, WordPress Vulnerability
CVE-2026-48907 is a CVSS 10.0 flaw in the Joomla Content Editor plugin. Attackers upload PHP web shells through unauthenticated profile imports. CISA orders federal agencies to patch by June 19.
What WebPulse reported · 2 analyses
Joomla JCE Scores a Perfect 10: CISA KEV, PHP Web Shells, Zero Authentication Required
CVE-2026-48907 is a CVSS 10.0 flaw in the Joomla Content Editor plugin. Attackers upload PHP web shells through unauthenticated profile imports. CISA orders fed
June 18, 2026
June 2026: Six CVSS 9.8 Vulnerabilities. 1.14 Million WordPress Sites.
Six critical vulnerabilities actively exploited at the same time. 29,300+ attacks per day on one plugin alone. A premium plugin supply-chain compromised. The Wo
June 9, 2026
Related vulnerabilities