PT-2026-65790 · Joomla · Joomla Content Editor

·

CVE-2026-65891

·

Published

2026-07-29

·

Updated

2026-08-05

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Joomla Content Editor (JCE) versions prior to 2.20.2
Description Improper input validation in the file rename functionality allows an authenticated user with file management permissions to rename files using invalid names. This can lead to the creation of hidden files and the unintended replacement of existing files at the destination path.
Recommendations Update Joomla Content Editor (JCE) to version 2.20.2 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11396
CVE-2026-65891

Affected Products

Joomla Content Editor