CVE-2026-48907 CRITICAL

Widget Factory Joomla Content Editor Vulnerability
Generated: 10 Oct 2026 20:37 • CVE Threat Intelligence

Description

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.

9.8
CVSS CRITICAL

Details

Published
16 Jun 2026 00:00
Modified
N/A
Source
CIRCL
Vendor
Widget Factory
Product
Joomla Content Editor
Fix Version
Vendor Patch / Mitigation Available