← Vulnerability feed

Vulnerability record · CVE-2026-48943 · published 25 June 2026

CVE-2026-48943: Joomlaworks k2 mass assignment vulnerability

Joomlaworks · K2

K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserForm=1` in a standard `com_users` `profile.save` POST, can write arbitrary values into the `notes`, `image`, and `plugins` columns of their own row in the `#__k2_users` table — none of which are exposed by the K2 frontend profile-edit form.

6.5 CVSS 3.1 Medium EPSS 0.30% · top 79.3% CWE-915 · Mass assignment
6.5CVSS 3.1 base score
0.30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
28 Jun 2026Last modified by NVD

Description

K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserForm=1` in a standard `com_users` `profile.save` POST, can write arbitrary values into the `notes`, `image`, and `plugins` columns of their own row in the `#__k2_users` table — none of which are exposed by the K2 frontend profile-edit form.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.getk2.org/ Product

Track CVE-2026-48943 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-19634Verot project verot unrestricted file upload vulnerabilityclass.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .ph…EPSS 4.2%9.8CVE-2019-19576Verot project verot unrestricted file upload vulnerabilityclass.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar…EPSS 26%7.5CVE-2018-7482Joomlaworks k2 path traversal vulnerabilityThe K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demons…EPSS 2.3%6.5CVE-2026-48941Joomlaworks k2 missing authorization vulnerabilityThe K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` c…EPSS 0.27%6.5CVE-2026-48944Joomlaworks k2 path traversal vulnerabilityThe K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::co…EPSS 0.44%6.3CVE-2026-48946Joomlaworks k2 unrestricted file upload vulnerabilityThe K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes t…EPSS 0.28%6.1CVE-2026-48942Joomlaworks k2 cross-site scripting vulnerabilityK2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping.EPSS 0.25%5.3CVE-2026-48945Joomlaworks k2 unrestricted file upload vulnerabilityThe K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only renames image files (gif/jpg/jp…EPSS 0.33%

Source: NIST National Vulnerability Database (record CVE-2026-48943), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.