Unrated severityNVD Advisory· Published Jun 25, 2026· Updated Jun 28, 2026
Joomla Extension - getk2.org - Stored-XSS in K2 extension for Joomla < 2.26
CVE-2026-48940
Description
A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose embedVideo POST field contains a raw `` tag; K2 stores it verbatim and renders it unescaped to any visitor of the article page.
Affected products
1Patches
Vulnerability mechanics
References
1- www.getk2.orgmitreproduct
News mentions
0No linked articles in our index yet.