VYPR
Unrated severityNVD Advisory· Published Jun 25, 2026· Updated Jun 28, 2026

Joomla Extension - getk2.org - Stored-XSS in K2 extension for Joomla < 2.26

CVE-2026-48940

Description

A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose embedVideo POST field contains a raw `` tag; K2 stores it verbatim and renders it unescaped to any visitor of the article page.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.