VendorsJoomlaWorksk2any version
Vulnerabilities

JoomlaWorks K2 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2019-19576
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
Published 2019-12-04 · Modified
9.81 PoCEPSS 0.264
CVE-2019-19634
class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.
Published 2019-12-17 · Modified
9.8EPSS 0.042
CVE-2026-48944
Joomla Extension - getk2.org - Exposure of sensitive files via attachment copy in K2 extension for Joomla < 2.26
Published 2026-06-25 · Analyzed
6.5EPSS 0.004
CVE-2026-48943
Joomla Extension - getk2.org - Authenticated user property mass-assignment in K2 extension for Joomla < 2.26
Published 2026-06-25 · Analyzed
6.5EPSS 0.003
CVE-2026-48941
Joomla Extension - getk2.org - Unauthenticated folder delete in K2 extension for Joomla < 2.26
Published 2026-06-25 · Analyzed
6.5EPSS 0.003
CVE-2026-48946
Joomla Extension - getk2.org - Privileged RCE vulnerability in K2 extension for Joomla < 2.26
Published 2026-06-25 · Analyzed
6.3EPSS 0.003
CVE-2026-48942
Joomla Extension - getk2.org - Stored-XSS in K2 extension for Joomla < 2.26
Published 2026-06-25 · Analyzed
6.1EPSS 0.003
CVE-2026-48945
Joomla Extension - getk2.org - Privileged RCE vulnerability in K2 extension for Joomla < 2.26
Published 2026-06-25 · Analyzed
5.3EPSS 0.003
CVE-2026-48940
Joomla Extension - getk2.org - Stored-XSS in K2 extension for Joomla < 2.26
Published 2026-06-25 · Analyzed
3.4EPSS 0.003