Widget Factory Joomla Content Editor Improper Access Control Vulnerability
High Listed in CISA KEV
Summary
Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Widget Factory:Joomla Content Editor
Sources
- CISA KEV DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2026-48907 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites reference
- https://www.joomlacontenteditor.net/support/changelog/editor reference
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk reference
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk reference
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV