• News
  • JCE Pro 2.9.99.4 released

JCE Pro 2.9.99.4 released

This is a security maintenance release and all users are encouraged to update as soon as possible.

Two related vulnerabilities have been identified and resolved in JCE Core and JCE Pro. All previous versions are affected.

An authenticated user could potentially access an Editor Profile that they are not assigned to and invoke filesystem actions available to that profile, but within the restrictions of that profile. Additionally, a directory parameter could be manipulated in a filesystem search function to list folder contents outside the configured directory.

Both issues have been resolved in 2.9.99.4. Exploitation required an active, authenticated Joomla session; unauthenticated access was not possible.

We were made aware of this issue via an external security report and completed our investigation and fix within 24 hours. We would like to thank the reporter for submitting their findings in good faith.

All JCE users should update to 2.9.99.4 at the earliest opportunity via the Joomla Update Manager or the JCE downloads area.

Please Note: JCE Pro 2.9.99 is compatible with Joomla 3, 4, 5 and 6, and does not require the Backwards Compatibility plugin in Joomla 5 or Joomla 6.

A changelog for this release is available to view here

Thank you to everyone who submitted bug reports and tested development versions. If you find any more issues please submit a ticket in the forum or on github.

Download and Installation

 JCE Pro is available for download with a JCE Pro Subscription.
If you already have a subscription, please make sure you set your key before updating

Instructions for installing and updating JCE for each Joomla version are available here