All vulnerabilities
HIGHKnown-exploitedexploited in the wild

CVE-2026-48907

Widget Factory · Joomla Content Editor

Summary

Widget Factory Joomla Content Editor Improper Access Control Vulnerability. Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.

References