CVE-2026-48907 in the Joomla JCE plugin lets unauthenticated attackers drop PHP web shells with a single crafted request.
The first proposed catalog of 'configuration smells' reveals widespread issues like context bloat, skill leakage, and ...