VendorsJoomlaWorksk2all versions
Vulnerabilities

JoomlaWorks K2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2019-19576
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
Published 2019-12-04 · Modified
9.81 PoCEPSS 0.264
CVE-2019-19634
class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.
Published 2019-12-17 · Modified
9.8EPSS 0.042
CVE-2018-7482
The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demonstrated by a view=media&task=connector&cmd=file&target=l1_../configuration.php&download=1 request. The specific pathname ../configuration.php should be base64 encoded for a valid attack. NOTE: the vendor disputes this issue because only files under the media-manager path can be downloaded, and the documentation indicates that sensitive information does not belong there. Nonetheless, 2.8.1 has additional blocking of .php downloads
Published 2018-02-28 · Modified
7.5EPSS 0.023
CVE-2026-48944
Joomla Extension - getk2.org - Exposure of sensitive files via attachment copy in K2 extension for Joomla < 2.26
Published 2026-06-25 · Analyzed
6.5EPSS 0.004
CVE-2026-48943
Joomla Extension - getk2.org - Authenticated user property mass-assignment in K2 extension for Joomla < 2.26
Published 2026-06-25 · Analyzed
6.5EPSS 0.003
CVE-2026-48941
Joomla Extension - getk2.org - Unauthenticated folder delete in K2 extension for Joomla < 2.26
Published 2026-06-25 · Analyzed
6.5EPSS 0.003
CVE-2026-48946
Joomla Extension - getk2.org - Privileged RCE vulnerability in K2 extension for Joomla < 2.26
Published 2026-06-25 · Analyzed
6.3EPSS 0.003
CVE-2026-48942
Joomla Extension - getk2.org - Stored-XSS in K2 extension for Joomla < 2.26
Published 2026-06-25 · Analyzed
6.1EPSS 0.003
CVE-2026-48945
Joomla Extension - getk2.org - Privileged RCE vulnerability in K2 extension for Joomla < 2.26
Published 2026-06-25 · Analyzed
5.3EPSS 0.003
CVE-2026-48940
Joomla Extension - getk2.org - Stored-XSS in K2 extension for Joomla < 2.26
Published 2026-06-25 · Analyzed
3.4EPSS 0.003