MEDIUMVulnerability

CVE-2026-65891

Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated user with file management permissions to rename files to otherwise invalid names, resulting in the creation of hidden files. The issue also allowed existing files at the destination path to be unintentionally replaced.

Properties

severity
MEDIUM
score
6.5
cve_id
CVE-2026-65891
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
published_at
2026-07-29T13:19:10.980
last_modified
2026-08-05T20:27:35.390

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Improper Input Validation

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (2)

[Product]
[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-65891 — Ninja Signal Threat Intelligence | Ninja Signal