CVE-2026-48942: Joomla Extension - getk2.org - Stored-XSS in K2 extension for Joomla < 2.26
Published Jun 25, 2026
·Updated
K2 ≤ 2.26 renders the #k2users.image column directly into HTML src attributes via two distinct templates, in both cases without HTML escaping.
Affected Software
2 affected components
Joomla K2 extension (getk2.com)<=2.26
JoomlaWorks K2 Joomla\!<=2.26
Event History
Jun 25, 2026
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48942?
CVE-2026-48942 has a medium severity score of 6.1 according to the CVSS 3.1 standard.
2
How do I fix CVE-2026-48942?
To fix CVE-2026-48942, update the K2 extension to version 2.26 or later, which addresses the stored XSS vulnerability.
3
What type of vulnerability is CVE-2026-48942?
CVE-2026-48942 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the K2 extension for Joomla.
4
Which versions are affected by CVE-2026-48942?
CVE-2026-48942 affects all versions of the K2 extension for Joomla prior to 2.26.
5
What does CVE-2026-48942 impact?
CVE-2026-48942 impacts user profile images rendered in HTML `src` attributes without proper HTML escaping, leading to potential XSS attacks.