CVE Explorer
CVE-2026-65891
Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated user with file management permissions to rename files to otherwise invalid names, resulting in the creation of hidden files. The issue also allowed existing files at the destination path to be unintentionally replaced.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Joomla Content Editor (JCE) extension for Joomla","vendor":"joomlacontenteditor.net","versions":[{"status":"affected","version":"1.0.0-2.9.99.9"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b94cded23f3aac742ef25353299d10a2cbc1be3265f841c3ef61a8ab9a9df20b · sha256:fc40922c5944f53f… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:b94cded23f3aac742ef25353299d10a2cbc1be3265f841c3ef61a8ab9a9df20b · sha256:fc40922c5944f53f… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-20","description":"CWE-20 – Improper Input Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b94cded23f3aac742ef25353299d10a2cbc1be3265f841c3ef61a8ab9a9df20b · sha256:fc40922c5944f53f… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["product"],"url":"https://www.joomlacontenteditor.net/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b94cded23f3aac742ef25353299d10a2cbc1be3265f841c3ef61a8ab9a9df20b · sha256:fc40922c5944f53f… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.