Skip to main content

JCE and Joomla 3

Said stopped, kept shipping

Said in February 2026 that JCE 3.0 would remove official Joomla 3 support, then lowered the 2.9.99 Joomla 3 floor to 3.9, published a free security patch reaching back to 2.7.x, and was still releasing the 2.9.99 line for Joomla 3 in September 2026.

Joomla extensions covered: JCE Pro, JCE Core. JCE website

What they said

  • “Remove official support for Joomla 3”

    Said 11 Feb 2026Read it on their siteChecked 2 Oct 2026

  • “This ensures Joomla 3 users remain supported for critical fixes while development progresses toward JCE Pro 3.x.”

    Said 11 Feb 2026Read it on their siteChecked 2 Oct 2026

What they did

  1. Free security patch published for JCE 2.7.x to 2.9.x, for sites that cannot update to 2.9.99.6 or later

    Source

  2. JCE 2.9.99.7 allows installation on Joomla 3.9 and later

    Source

  3. JCE 2.9.99.11 released on the 2.9.99 line that still runs on Joomla 3

    Source

Known Joomla 3 vulnerabilities

  • Critical

    JCE (com_jce) below 2.9.99.6 - Unauthenticated Arbitrary File Upload (RCE) and Directory Traversal

    Affected: ≥ 2.7.0 and < 2.9.99.6

    CVE-2026-48907

Our coverage

See which of your sites run JCE Pro

Connect one site and mySites.guru audits it free, with no card. You see the core vulnerabilities still open on it, the extensions with known holes, and a one-click fix for the core ones.

Is a Joomla 3 site hacked right now?

We clean it for a single fixed fee of £120 per incident, usually the same day. We screen it before you pay, so in the rare case it cannot be fixed you are not charged, and non-subscribers get a free month of mySites.guru with it. Get it fixed

Keep your Joomla 3 sites patched while you plan the move

One free audit of one site, no card. It shows the core vulnerabilities still open and the extensions with known holes.

Audit a Joomla 3 site free