JCE and Joomla 3
Said in February 2026 that JCE 3.0 would remove official Joomla 3 support, then lowered the 2.9.99 Joomla 3 floor to 3.9, published a free security patch reaching back to 2.7.x, and was still releasing the 2.9.99 line for Joomla 3 in September 2026.
Joomla extensions covered: JCE Pro, JCE Core. JCE website
What they said
“Remove official support for Joomla 3”
Said 11 Feb 2026Read it on their siteChecked 2 Oct 2026
“This ensures Joomla 3 users remain supported for critical fixes while development progresses toward JCE Pro 3.x.”
Said 11 Feb 2026Read it on their siteChecked 2 Oct 2026
Known Joomla 3 vulnerabilities
- Critical
JCE (com_jce) below 2.9.99.6 - Unauthenticated Arbitrary File Upload (RCE) and Directory Traversal
Affected: ≥ 2.7.0 and < 2.9.99.6
Our coverage
- JCE 2.9.99.10 Fixes Another Security Issue
JCE 2.9.99.10 patches a file rename flaw letting a privileged user create a hidden file in the folder they were browsing. The release hardens more too.
- A New mySites.guru Tool to Find, and Fix, the JCE Profiles Hack (June 2026)
mySites.guru now has a dedicated check that finds rogue JCE editor profiles and webshells across your Joomla sites, then lets you clean and patch them.
- JCE Pro 2.9.99.6 Is a Hardening Release After a Full Audit of Joomla's Most-Installed Editor
JCE Pro 2.9.99.6 follows a four-day security audit of the editor, narrowing entry points and hardening input validation. Recommended for every JCE site.
- JCE Free/Pro 2.9.99.5 Patches an Unauthenticated File Upload in Joomla's Most-Installed Editor
JCE Free and JCE Pro 2.9.99.5 patch an unauthenticated editor profile upload that could upload arbitrary files. Update every Joomla site running JCE.
- JCE Free/Pro 2.9.99.4 Patches Two Authenticated Vulnerabilities in Joomla's Most Popular Editor
JCE Free and JCE Pro 2.9.99.4 patch an Editor Profile authentication bypass and a directory traversal in filesystem search. Update JCE today.
See which of your sites run JCE Pro
Connect one site and mySites.guru audits it free, with no card. You see the core vulnerabilities still open on it, the extensions with known holes, and a one-click fix for the core ones.
Is a Joomla 3 site hacked right now?
We clean it for a single fixed fee of £120 per incident, usually the same day. We screen it before you pay, so in the rare case it cannot be fixed you are not charged, and non-subscribers get a free month of mySites.guru with it. Get it fixed
Keep your Joomla 3 sites patched while you plan the move
One free audit of one site, no card. It shows the core vulnerabilities still open and the extensions with known holes.