VYPR
Medium severity6.5NVD Advisory· Published Jun 25, 2026· Updated Jun 28, 2026

CVE-2026-48941

CVE-2026-48941

Description

The K2 frontend item.checkin task accepts an unauthenticated sigProFolder query parameter and uses it directly to address a JFolder::delete() call under /media/k2/galleries/

Affected products

1
  • cpe:2.3:a:joomlaworks:k2:*:*:*:*:*:joomla\!:*:*
    Range: <=2.26

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.