VYPR

Jce

by Widgetfactorylimited

CVEs (2)

  • CVE-2015-7339HigMar 9, 2020
    risk 0.57cvss 8.8epss 0.01

    JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script.

  • CVE-2026-65891MedJul 29, 2026
    risk 0.42cvss 6.5epss 0.00

    Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated user with file management…