CVE-2026-48907
Widget Factory Joomla Content Editor Improper Access Control Vulnerability
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Deadline for federal agencies: 2026-06-19.
6 articles across 5 outlets · first covered Jun 16, 2026 · latest Jun 17, 2026
Coverage timeline
-
CISA flags critical Joomla JCE bug enabling remote code executionsecurityaffairs.com · Jun 17, 2026
-
AdGuard blocks Joomla exploit and launches email tracking shieldsecurityonline.info · Jun 17, 2026
-
Joomla and LiteSpeed Bugs Let Attackers Run Code, Gain Rootwww.securityweek.com · Jun 17, 2026
-
WooCommerce stores hit by payment skimmer (CVE-2026-48907)securityonline.info · Jun 17, 2026
-
CISA Adds CVE-2026-48907 Joomla Editor Flaw to Known Exploited Listwww.cisa.gov · Jun 16, 2026
-
CISA adds critical Joomla editor flaw CVE-2026-48907 to KEVcisa.gov · Jun 16, 2026