Security
Loading…

CVE-2026-48907

UNKNOWNKnown Exploited
Description

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.

Timeline
Published:June 16th, 2026 12:00 AM
Last modified:June 16th, 2026 12:00 AM
Added to KEV:June 16th, 2026
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

Widget Factory

Products

Joomla Content Editor
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute