Widgetfactorylimited

Jce

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 29.07.2026 13:19:10
  • Zuletzt bearbeitet 05.08.2026 20:27:35

Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated user...

Warnung Medienbericht
  • EPSS 68.83%
  • Veröffentlicht 05.06.2026 07:31:30
  • Zuletzt bearbeitet 23.07.2026 07:10:00

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

Exploit
  • EPSS 1.13%
  • Veröffentlicht 09.03.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 02:36:37

JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script.