Widgetfactorylimited's vulnerability footprint centers on a narrowly scoped line of Java Cryptography Extension (JCE) products, with the observed exposure rooted in file-handling and upload-validation mechanisms. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Widgetfactorylimited over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-48907CRITICAL A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution. | Jun 5, 2026 | 9.8 | 98 | YES | YES |
CVE-2015-7339HIGH JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script. | Mar 9, 2020 | 8.8 | 22 | NO | NO |
CVE-2011-5134MEDIUM Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the JCE component before 2.0.18 for Joomla! allows remote authenticated users with the author privil | Aug 30, 2012 | 6.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Widgetfactorylimited.
Media articles that mention a CVE ID that affects a product developed by Widgetfactorylimited — matched by CVE ID, not by vendor name.