high Known exploited

CVE-2026-48907

Widget Factory Joomla Content Editor Improper Access Control Vulnerability

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.

Published
Jun 16, 2026
Vendor
Widget Factory
Product
Joomla Content Editor
CISA due date
2026-06-19
Source
merged

References

Check your website: Korisec scans for exposed services, weak TLS, missing headers, and WordPress plugin risks. Run a free scan or start a trial.

← Back to CVE Tracker · Official record: cve.org