CVE-2026-65891

Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated user with file management permissions to rename files to otherwise invalid names, resulting in the creation of hidden files. The issue also allowed existing files at the destination path to be unintentionally replaced.
References
Link Resource
https://www.joomlacontenteditor.net/ Product
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:widgetfactorylimited:jce:*:*:*:*:core:joomla\!:*:*
cpe:2.3:a:widgetfactorylimited:jce:*:*:*:*:pro:joomla\!:*:*

History

No history.

Information

Published : 2026-07-29 13:19

Updated : 2026-08-05 20:27


NVD link : CVE-2026-65891

Mitre link : CVE-2026-65891

CVE.ORG link : CVE-2026-65891


JSON object : View

Products Affected

widgetfactorylimited

  • jce
CWE
CWE-20

Improper Input Validation