Joomla Content Editor vulnerabilities
1 published alerts for Widget Factory Joomla Content Editor.
Actively exploited (KEV)
Widget Factory Joomla Content Editor Improper Access Control Vulnerability
Widget Factory Joomla Content Editor is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-48907). Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users. CISA remediation due date: 2026-06-19. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.