CVE-2026-48946
Published Jun 25, 2026The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes them under the K2 web user. A K…
- evidence mentions
- 1
- Buzz score
- 11.9