[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":43,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":50,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":56,"vulnerability-29501":63},[4,15,23,28],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"wp2shell (Vuln DB homepage)","wp2shell-vuln-db","Emergency CVE response: detection & exploitation now available for *wp2shell*, the critical WP RCE chain","https://pentest-tools.com/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",false,[11],"/vulnerabilities-exploits/","See CVE details","secondary","wp2shell",{"title":16,"slug":17,"text":18,"link":19,"external":9,"targets":20,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - exploitation)","wp2shell-cve-page-exploit","Validate wp2shell exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.","https://pentest-tools.com/pricing",[21],"/vulnerabilities-exploits/wp2shell-wordpress-core-690-694-and-700-701-pre-auth-batch-route-confusion-leading-to-sql-injection_29452","Explore plans",{"title":24,"slug":25,"text":18,"link":19,"external":9,"targets":26,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - detection)","wp2shell-cve-page",[27],"/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",{"title":29,"slug":30,"text":31,"link":32,"external":9,"targets":33,"cta":42,"variant":13,"campaign_id":30},"DEF CON AI pentests launch","def-con-ai-pentests","We’re launching AI Pentests at DEF CON 34","https://pentest-tools.com/events/defcon-34-2026",[34,35,36,37,38,39,40,41],"/","/website-vulnerability-scanning/website-scanner","/network-vulnerability-scanning/network-security-scanner-online","/information-gathering/find-subdomains-of-domain","/network-vulnerability-scanning/port-scanner-online-nmap","/product","/website-vulnerability-scanning/discover-hidden-directories-and-files","/insights","See you there",["Island",44],{"key":45,"params":46,"result":48},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":47},"{}",{"head":49},{},["Island",51],{"key":52,"params":53,"result":54},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":47},{"head":55},{},["Island",57],{"key":58,"params":59,"result":61},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":60},"{\"text-color\":\"gray\"}",{"head":62},{},{"id":64,"detectable_with":65,"vuln_details":71,"vuln_id":96,"name":97,"published":98,"updated":98},29501,{"tool":66,"engine":69},{"id":67,"name":68},1,"Network Scanner",{"id":67,"name":70},"Sniper",{"id":64,"codename":72,"description":73,"severity":74,"risk_description":75,"public_description":76,"public_recommendation":77,"recommendation":78,"references":79,"cvssv3":84,"epss_score":85,"epss_percentile":86,"cve":87,"in_cisa_catalog":89,"date":90,"software_type":91,"vendor":92,"product":93,"ptt_exploit_capabilities":94},null,"We found that the target Joomla site is running the JCE (Joomla Content Editor) extension, version 2.9.99.4 or earlier, which is vulnerable to an unauthenticated remote code execution. The vulnerability stems from a missing authentication check in the JCE profile-import feature (com_jce, task=profiles.import), which lets an unauthenticated attacker upload an XML file containing embedded PHP code. The uploaded file is stored under a web-accessible tmp/ directory without proper extension or content validation, and because Joomla's default configuration allows PHP execution inside tmp/, the attacker can execute arbitrary code by requesting the uploaded file directly.","critical","The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network.","The JCE (Joomla Content Editor) extension for Joomla, versions up to and including 2.9.99.4, is vulnerable to unauthenticated remote code execution due to an unrestricted file upload in its profile-import feature. An attacker can submit a crafted multipart/form-data request to the profile-import endpoint (com_jce, task=profiles.import) carrying an XML file with embedded PHP, which the extension stores under a web-accessible temporary directory. Because the import flow requires no authentication and performs insufficient validation, the uploaded PHP can be requested and executed remotely.","Update the JCE Editor extension to version 2.9.99.5 or later.","We recommend updating the JCE Editor extension to version 2.9.99.5 or later; if immediate update is not possible, restrict access to the affected Joomla component and remove or harden the profile-import functionality to prevent unauthenticated uploads.",[80,81,82,83],"https://nvd.nist.gov/vuln/detail/CVE-2026-48907","https://github.com/advisories/GHSA-c3f5-4g7f-qjqj","https://www.joomlacontenteditor.net/support/changelog/editor","https://github.com/ywh-jfellus/CVE-2026-48907",10,0.55914,0.98947,[88],"CVE-2026-48907",true,"2026-06-05T00:00:00Z","Joomla Extension","Joomla Content Editor","JCE",[95],"RCE","NETSCAN-SNIPER-CVE-2026-48907","Joomla JCE - Remote Code Execution","2026-07-21T00:00:00Z"]