CISA Known Exploited Vulnerability
CVE-2026-48907 — Joomla Actively Exploited CVE
Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticate
CISA catalog entry
Product
Joomla Content Editor
Vendor
Widget Factory
Added to KEV
2026-06-16
Remediation due
2026-06-19
What WebPulse reported · 1 analysis
Related vulnerabilities