CVE-2026-65891
Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.9.99.10
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated user with file management permissions to rename files to otherwise invalid names, resulting in the creation of hidden files. The issue also allowed existing files at the destination path to be unintentionally replaced.
| CWE | CWE-20 |
| Vendor | joomlacontenteditor.net |
| Product | joomla content editor (jce) extension for joomla |
| Published | Jul 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for joomlacontenteditor.net joomla content editor (jce) extension for joomla
Be the first to know when new unknown vulnerabilities affecting joomlacontenteditor.net joomla content editor (jce) extension for joomla are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
Affected Versions
joomlacontenteditor.net / Joomla Content Editor (JCE) extension for Joomla
1.0.0-2.9.99.9
References
Credits
MΓΌrrez