CVE-2026-48907CISA KEVEPSS p98.9%

CVE-2026-48907Widget Factory Joomla Content Editor Improper Access Control Vulnerability

Widget Factory / Joomla Content Editor

Description

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.

Scoring

CVSS 9.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS55.91% probability of exploitation · percentile 98.9% · 2026-07-31T12:03:43Z
Last modified2026-07-23

CISA KEV entry

Added to KEV: 2026-06-16

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-22204
CVE
Joomla! Improper Access Control Vulnerability
CVE
CVE-2025-29287
CVE
CVE-2025-26854
CVE
CVE-2026-29014
CVE
CVE-2026-41934
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.