Improper Input Validation in Joomla Content Editor by Joomla
CVE-2026-65891

Currently unrated

What is CVE-2026-65891?

The Joomla Content Editor (JCE) prior to version 2.20.2 is affected by an improper input validation vulnerability. This flaw permits authenticated users with file management permissions to rename files, even to invalid names, which can lead to the creation of hidden files. Additionally, this flaw may result in unintended overwrite of existing files at the destination path. This vulnerability poses a risk to the integrity and security of files managed by JCE.

Affected Version(s)

Joomla Content Editor (JCE) extension for Joomla 1.0.0-2.9.99.9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MĂĽrrez
.