CVE-2026-48907: Widget Factory Joomla Content Editor Improper Access Control Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-06-16. EPSS: 16.2% chance of exploitation in the next 30 days.

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

Affected products

Published 2026-06-05. Last modified 2026-07-23.