Каталог CVE

Расширение: JCE

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 8

Расширение: JCE
Критическая CVSS 10.0

CVE-2026-48907

РасширениеJCE
Разработчикjoomlacontenteditor

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

05.06.2026 Требует внимания
Высокая CVSS 8.8

CVE-2015-7339

РасширениеJCE
Разработчикlabs.integrity.pt

JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script.

09.03.2020
Средняя CVSS 6.0

CVE-2011-5134

РасширениеWidgetfactorylimited Com Jce
Разработчикsecunia

Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the JCE component before 2.0.18 for Joomla! allows remote authenticated users with the author privileges to e…

30.08.2012
Средняя CVSS 6.0

CVE-2012-2902

Разработчикosvdb

Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the Joomla Content Editor (JCE) component before 2.1 for Joomla!, when chunking is set to greater than zero,…

21.05.2012
Средняя CVSS 4.3

CVE-2012-2901

Разработчикsecunia

Cross-site scripting (XSS) vulnerability in the Profile List in the Joomla Content Editor (JCE) component before 2.1 for Joomla! allows remote attackers to inject arbitrary web script or HT…

21.05.2012
Высокая CVSS 7.5

CVE-2006-6419

Разработчикsecunia

jce.php in the JCE Admin Component in Ryan Demmer Joomla Content Editor (JCE) 1.1.0 beta 2 and earlier for Joomla! (com_jce) allows remote attackers to include and possibly execute arbitrar…

10.12.2006
Средняя CVSS 6.8

CVE-2006-6420

Разработчикsecunia

Multiple cross-site scripting (XSS) vulnerabilities in jce.php in the JCE Admin Component in Ryan Demmer Joomla Content Editor (JCE) 1.1.0 beta 2 and earlier for Joomla! (com_jce) allow rem…

10.12.2006
Средняя CVSS 6.8

CVE-2006-6166

Разработчикforum.joomla

Cross-site scripting (XSS) vulnerability in jce.php in the JCE Admin Component in Ryan Demmer Joomla Content Editor (JCE) 1.0.4 for Joomla! (com_jce), without the 20060821 jce_patch, allows…

29.11.2006