CVE-2026-48907CISA KEVEPSS p98.9%
CVE-2026-48907Widget Factory Joomla Content Editor Improper Access Control Vulnerability
Widget Factory / Joomla Content Editor
Description
Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
Scoring
| CVSS | 9.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 55.91% probability of exploitation · percentile 98.9% · 2026-07-31T12:03:43Z |
| Last modified | 2026-07-23 |
CISA KEV entry
Added to KEV: 2026-06-16
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.