CVE-2026-48907: Widget Factory Joomla Content Editor Improper Access
Widget Factory Joomla Content Editor Improper Access Control Vulnerability. Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
- CISA KEV-listed (remediation due 2026-06-19)
- EPSS 66.0% (99.2% percentile)
- CVSS 10 critical