← Back to browse · API

CVE-2026-48907

Severity
CRITICAL
CVSS
10.0
EPSS
0.55914
Risk score
84.57
CISA KEV
Yes
PoC
Yes
Published
2026-06-16
Modified
2026-06-16
First seen
2026-08-05
Aliases
EUVD-2026-34789, GHSA-C3F5-4G7F-QJQJ
Products
Widget Factory:Joomla Content Editor, joomlacontenteditor.net:Joomla Content Editor (JCE) extension for Joomla 1.0.0-2.9.99.4, widgetfactorylimited:jce
Sources
nvd CVE-2026-48907
euvd EUVD-2026-34789
packetstorm 5c2ace37fd387af83dc074cb|CVE-2026-48907
cisa.gov CVE-2026-48907
packetstorm b5100d8cb0161cac27987b82|CVE-2026-48907
github 1bae61e8f8a6258ac948ad43|CVE-2026-48907

Description

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.

References