CVE-2015-7339: Widgetfactorylimited Jce

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script.

Affected products

Published 2020-03-09. Last modified 2026-06-17.