6.5
CVE-2026-65891
- EPSS 0.2%
- Veröffentlicht 29.07.2026 13:19:10
- Zuletzt bearbeitet 05.08.2026 20:27:35
- CVE-Watchlists
- Unerledigt
Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.9.99.10
Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated user with file management permissions to rename files to otherwise invalid names, resulting in the creation of hidden files. The issue also allowed existing files at the destination path to be unintentionally replaced.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Widgetfactorylimited ≫ Jce SwEditioncore SwPlatformjoomla! Version < 2.20.2
Widgetfactorylimited ≫ Jce SwEditionpro SwPlatformjoomla! Version < 2.20.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.095 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://www.joomlacontenteditor.net/