CVE-2015-7339: Widgetfactorylimited Jce
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script.
Affected products
- Widgetfactorylimited Jce: from 2.5.0, up to and including 2.5.2
Published 2020-03-09. Last modified 2026-06-17.