PT-2026-52465 · Getk2.Com · K2 Extension For Joomla
Matan Bahar
+1
·
Published
2026-06-25
·
Updated
2026-06-25
·
CVE-2026-48942
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
K2 ≤ 2.26 renders the
# k2 users.image column directly into HTML src attributes via two distinct templates, in both cases without HTML escaping.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
K2 Extension For Joomla