Vulnerabilities
Vulnerable Software
Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated user with file management permissions to rename files to otherwise invalid names, resulting in the creation of hidden files. The issue also allowed existing files at the destination path to be unintentionally replaced.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-07-29
CVE-2026-48907
Known exploited
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
CVSS Score
10.0
EPSS Score
0.781
Published
2026-06-05


Contact Us

Shodan ® - All rights reserved