The Joomla Content Editor (JCE) versions before 2.20.2 are affected by a vulnerability that allows authenticated users with file management permissions to create hidden files and unintentionally overwrite existing files due to improper input validation in the file rename functionality. This issue can lead to unintended file overwrites and potential security risks. The vulnerability was addressed in JCE ve [truncated]
Known exploitedjoomlacontenteditor.netCVE published 2026-06-16
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution. This vulnerability has a CVSS score of 10 and is considered CRITICAL.