CVE-2026-48940: Joomla Extension - getk2.org - Stored-XSS in K2 extension for Joomla < 2.26
Published Jun 25, 2026
·Updated
A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose embedVideo POST field contains a raw <script> tag; K2 stores it verbatim and renders it unescaped to any visitor of the article page.
Affected Software
2 affected components
Joomla extension getk2.com (K2)<2.26
JoomlaWorks K2 Joomla\!<=2.26
Event History
Jun 25, 2026
CVE Published
via MITRE·03:26 PM
Data Sourced
via MITRE·03:26 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48940?
The severity of CVE-2026-48940 is low, with a CVSS score of 3.4.
2
How do I fix CVE-2026-48940?
To fix CVE-2026-48940, upgrade the K2 extension for Joomla to version 2.26 or later.
3
What type of vulnerability is CVE-2026-48940?
CVE-2026-48940 is a Stored Cross-Site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2026-48940?
CVE-2026-48940 affects Joomla users with K2 'create item' rights, primarily those on versions less than 2.26.
5
What could be the impact of CVE-2026-48940?
The impact of CVE-2026-48940 allows an attacker to inject JavaScript into an article, potentially affecting visitors of that article.