Joomla! Extension 'JCE' < 2.9.99.5 Remote Code Execution

critical Nessus Plugin ID 321523

Version 1.4

Jul 23, 2026, 8:43 AM

  • Exploit attributes ("Exploit framework core" set to "True")

Plugin Feed: 202607230843

Version 1.3

Jun 21, 2026, 5:21 AM

  • CVSS metrics ("Cvssv4 supplemental" set to "CVSS:4.0/AU:Y/U:Red")
  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:F/RL:OF/RC:C")
  • CVSS temporal metrics ("CVSSv3 temporal vector" set to "CVSS:3.0/E:F/RL:O/RC:C")
  • CISA reference
  • CVSS metrics ("Cvssv4 threat score" set to 10.0)

Plugin Feed: 202606210521

Version 1.2

Jun 20, 2026, 5:45 PM

  • CVSS metrics ("Cvssv4 supplemental" set to "CVSS:4.0/AU:Y/U:Red")
  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:F/RL:OF/RC:C")
  • CVSS temporal metrics ("CVSSv3 temporal vector" set to "CVSS:3.0/E:F/RL:O/RC:C")

Plugin Feed: 202606201745

Version 1.1

Jun 19, 2026, 1:00 AM

  • New

Plugin Feed: 202606190100

* Changelogs are generally available for changes made after Nov 1, 2022