VYPR
Low severity3.4NVD Advisory· Published Jun 25, 2026· Updated Jun 28, 2026

CVE-2026-48940

CVE-2026-48940

Description

A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose embedVideo POST field contains a raw `` tag; K2 stores it verbatim and renders it unescaped to any visitor of the article page.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.