U.S. CISA adds Widget Factory Joomla Content Editor flaw to its Known Exploited Vulnerabilities catalog
ID: 76333305-44f2-5339-bb21-d2e7b8b4e6e1
STIX ID: report--76333305-44f2-5339-bb21-d2e7b8b4e6e1
Feed Name: Security Affairs
Threat Score
**CISA adds Joomla Content Editor (JCE) vulnerability CVE-2026-48907 (CVSS 10.0) to its Known Exploited Vulnerabilities catalog:** an improper access control in JCE 1.0.0–2.9.99.4 allows unauthenticated creation of editor profiles leading to PHP upload and remote code execution; fixed in 2.9.99.5 (June 3, 2026) and federal agencies were ordered to remediate by June 19, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
