A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; K2 stores it verbatim and renders it unescaped to any visitor of the article page.
References
Link Providers
https://www.getk2.org/ cve-icon
History

Thu, 25 Jun 2026 15:45:00 +0000

Type Values Removed Values Added
Description A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; K2 stores it verbatim and renders it unescaped to any visitor of the article page.
Title Joomla Extension - getk2.com - Stored-XSS in K2 extension for Joomla < 2.26
Weaknesses CWE-79
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-06-25T17:03:33.486Z

Reserved: 2026-05-26T16:47:13.550Z

Link: CVE-2026-48940

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-25T16:15:15Z