Low severity3.4NVD Advisory· Published Jun 25, 2026· Updated Jun 28, 2026
CVE-2026-48940
CVE-2026-48940
Description
A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose embedVideo POST field contains a raw `` tag; K2 stores it verbatim and renders it unescaped to any visitor of the article page.
Affected products
2Patches
Vulnerability mechanics
References
1- www.getk2.orgnvdProduct
News mentions
0No linked articles in our index yet.