Widgetfactorylimited Jce vulnerabilities
3 known vulnerabilities affecting widgetfactorylimited/jce.
Total CVEs
3
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-48907P1CRITICALCVSS 9.8KEVPoCfixed in 2.9.99.52026-06-05
CVE-2026-48907 [CRITICAL] CWE-284 CVE-2026-48907: A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles fo
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
nvd
CVE-2015-7339P3HIGHCVSS 8.8≥ 2.5.0, ≤ 2.5.22020-03-09
CVE-2015-7339 [HIGH] CWE-434 CVE-2015-7339: JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an im
JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script.
nvd
CVE-2026-65891P3MEDIUMCVSS 6.5fixed in 2.20.22026-07-29
CVE-2026-65891 [MEDIUM] CWE-20 CVE-2026-65891: Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite
Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated user with file management permissions to rename files to otherwise invalid names, resulting in the creation
nvd