Joomla JCE profile import command execution

Added: 06/23/2026

Background

JCE is a content editor for Joomla.

Problem

A vulnerability in JCE allows an unauthenticated user to execute arbitrary commands by importing a specially crafted editor profile.

Resolution

Upgrade to JCE 2.9.99.5 or higher.

References

https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites

Back to exploit index