Joomla · Joomla Content Editor · CVE-2026-65891
**Name of the Vulnerable Software and Affected Versions**
Joomla Content Editor (JCE) versions prior to 2.20.2
**Description**
Improper input validation in the file rename functionality allows an authenticated user with file management permissions to rename files using invalid names. This can lead to the creation of hidden files and the unintended replacement of existing files at the destination path.
**Recommendations**
Update Joomla Content Editor (JCE) to version 2.20.2 or later.