Skip to content
Vulnerability intelligence

CVE-2026-3844 — Joomla, WordPress Vulnerability

CVE-2026-48907 is a CVSS 10.0 flaw in the Joomla Content Editor plugin. Attackers upload PHP web shells through unauthenticated profile imports. CISA orders federal agencies to patch by June 19.

CVSS 9.8 Joomla WordPress 2026