CyberSecurityBoardThreat Intel · CVEs · Products
Cyber Companies

Widget Factory: Developer of Joomla Content Editor (JCE)

June 25, 2026

Widget Factory is the developer of the Joomla Content Editor (JCE) extension, which was found to contain a critical improper access control vulnerability (CVE-2026-48907). The company released a patch in version 2.9.99.5 on June 3, 2026.