CVE-2026-48907: Widget Factory Joomla Content Editor Improper Access Control Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-06-16. EPSS: 16.2% chance of exploitation in the next 30 days.
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
Affected products
- Widgetfactorylimited Jce: before 2.9.99.5 (fixed in 2.9.99.5)
Published 2026-06-05. Last modified 2026-07-23.