logo

U.S. CISA adds Widget Factory Joomla Content Editor flaw to its Known Exploited Vulnerabilities catalog

ID: 76333305-44f2-5339-bb21-d2e7b8b4e6e1

STIX ID: report--76333305-44f2-5339-bb21-d2e7b8b4e6e1

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-06-17

Date Updated: 2026-06-18

Author: Pierluigi Paganini

...
...

**CISA adds Joomla Content Editor (JCE) vulnerability CVE-2026-48907 (CVSS 10.0) to its Known Exploited Vulnerabilities catalog:** an improper access control in JCE 1.0.0–2.9.99.4 allows unauthenticated creation of editor profiles leading to PHP upload and remote code execution; fixed in 2.9.99.5 (June 3, 2026) and federal agencies were ordered to remediate by June 19, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.