Executive brief
Joomla Content Editor (JCE), a popular content creation tool for the Joomla website platform, contains a flaw in its file management system. An authorized user with permissions to manage files could rename files in a way that creates hidden files or accidentally overwrites existing data. This could lead to data loss or the hiding of malicious files on the web server.
Technical details
An improper input validation vulnerability exists in the file rename functionality of Joomla Content Editor (JCE) versions prior to 2.20.2. An authenticated attacker with file management permissions can exploit this by providing specially crafted filenames that bypass validation checks. This allows for the creation of hidden files (e.g., files starting with a dot) or the unintended replacement of existing files at the destination path. The vulnerability is tracked as CWE-20 and was addressed in version 2.20.2.
Affected products
- joomlacontenteditor.net Joomla Content Editor (JCE) extension for Joomla 1.0.0 through 2.9.99.9 (versions prior to 2.20.2)
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory