RaqibCTI
CVE

CVE-2026-48907

P2
Widget Factory Joomla Content Editor Improper Access Control Vulnerability
Widget Factory · Joomla Content Editor
Date added (CISA)
2026-06-16
Remediation due
2026-06-19
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date
Associated with
Related to
  • Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff · SPECTREcampaignCorrelated cluster2026-09-16
  • DysphoriacampaignCorrelated cluster2026-08-24

Description

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.

Source: NVD ↗ · CISA KEV Catalog ↗