ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

CVE-2026-48907

CRITICAL Export PDF

Widget Factory Joomla Content Editor Vulnerability

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.

CVSS Score
9.8
CRITICAL
Published
16 Jun 2026 00:00
Modified
N/A
Vendor
Widget Factory
Product
Joomla Content Editor
Source
CIRCL

Affected Versions

Fix Vendor Patch / Mitigation Available

Weaknesses (CWE)

CWE-284

Affected Systems

Widget Factory
Joomla Content Editor
Widget Factory
Joomla Content Editor

KEV Status

Known Exploited Vulnerability