CVE-2026-48907CISA KEVEPSS p96.9%
CVE-2026-48907Widget Factory Joomla Content Editor Improper Access Control Vulnerability
Widget Factory / Joomla Content Editor
Description
Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
Scoring
| CVSS | 9.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 16.19% probability of exploitation · percentile 96.9% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-23 |
CISA KEV entry
Added to KEV: 2026-06-16
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.