JCE (com_jce) below 2.9.99.6 - Unauthenticated Arbitrary File Upload (RCE) and Directory Traversal
Affected versions: ≥ 2.7.0 and < 2.9.99.6
Joomla extension security alerts (22 Aug) Fabrik 4.7.2ZOO: unauth RCEPhoca Cart: unauth SQLiJCE 2.9.99.10SP Page Builder RCE
mySites.guru tracks 3vulnerabilities in com_jce. Every connected Joomla site is checked against them on each audit, and flagged if it runs an affected version.
Affected versions: ≥ 2.7.0 and < 2.9.99.6
Affected versions: ≥ 2.5.0 and ≤ 2.5.2
Affected versions: ≥ 2.9.99.6 and < 2.9.99.10

JCE 2.9.99.10 patches a file rename flaw that let a privileged user create a hidden file in the folder they were browsing. The release also hardens far more than its changelog lists.

mySites.guru now has a dedicated check that finds rogue JCE editor profiles and webshells across your Joomla sites, then lets you clean and patch them from one screen.

JCE Pro 2.9.99.6 follows a four-day security audit of the editor, narrowing entry points and hardening input validation. Strongly recommended for every Joomla site running JCE.

JCE Free and JCE Pro 2.9.99.5 patch an unauthenticated editor profile upload that could be used to upload arbitrary files to the server. Update every Joomla site running JCE now.

JCE Free and JCE Pro 2.9.99.4 patch an Editor Profile authentication bypass and a directory traversal in filesystem search. Update every Joomla site running JCE today.
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
CVE identifiers: CVE-2026-48907, CVE-2015-7339, CVE-2026-65891. Rules current as of 24 August 2026.