CVE-2026-48943 | getk2 K2 Extension 1.0-2.26 on Joomla profile.save K2UserForm dynamically-determined object attributes

SecurityVulns

A vulnerability categorized as critical has been discovered in getk2 K2 Extension 1.0-2.26 on Joomla. Affected by this vulnerability is the function profile.save. Such manipulation of the argument K2UserForm leads to dynamically-determined object attributes.

This vulnerability is traded as CVE-2026-48943. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More