vulnti.work

Widget Factory Joomla Content Editor Improper Access Control Vulnerability

High Listed in CISA KEV
CVECVE-2026-48907
First seen2026-06-16 00:00 UTC
Disclosed2026-06-16 00:00 UTC
Last updated2026-07-14 19:30 UTC
Channel statuspending_review

Summary

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Affected products

  • Widget Factory:Joomla Content Editor

Sources

  • CISA KEV DATABASE

Original Links

Timeline

  1. kev_added CISA KEV
  2. kev_ingest CISA KEV