CVE-2011-5134: Widgetfactorylimited Com Jce

Medium severity, CVSS 6.0. EPSS: 1.1% chance of exploitation in the next 30 days.

Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the JCE component before 2.0.18 for Joomla! allows remote authenticated users with the author privileges to execute arbitrary PHP code by uploading a file with a double extension, as demonstrated by .php.gif. NOTE: some of these details are obtained from third party information.

Affected products

  • Widgetfactorylimited Com Jce: up to and including 2.0.17; version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; …

Published 2012-08-30. Last modified 2026-06-16.