Skip to content
CISA Known Exploited Vulnerability

CVE-2026-48907 — Joomla Actively Exploited CVE

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticate

⚠ Actively exploited (CISA KEV) Joomla 2026
CISA catalog entry
Product
Joomla Content Editor
Vendor
Widget Factory
Added to KEV
2026-06-16
Remediation due
2026-06-19

CVE-2026-48907 is tracked in the CISA Known Exploited Vulnerabilities catalog. WebPulse monitors it as part of its framework security intelligence.

View CVE-2026-48907 on the NIST National Vulnerability Database →