Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.3 CVE-2026-48946 The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes t… K2 after 2.26 Fix from $1,6002026-06-25 MEDIUM 5.3 CVE-2026-48945 The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only renames image files (gif/jpg/jp… K2 after 2.26 Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-48941 The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` c… K2 after 2.26 Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-48943 K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserForm=… K2 after 2.26 Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-48944 The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::co… K2 after 2.26 Fix from $1,6002026-06-25 MEDIUM 6.1 CVE-2026-48942 K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping. K2 after 2.26 Fix from $1,6002026-06-25 CRITICAL 9.8 CVE-2019-19634 class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .ph… K2 1.0.3 / 2.0.4+ Fix from $2,3002019-12-17 CRITICAL 9.8 CVE-2019-19576EPSS 26% class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar… K2 1.0.3 / 2.0.4+ Fix from $2,3002019-12-04 HIGH 7.5 CVE-2018-7482 The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demons… K2 No fix yet Fix from $1,9502018-02-28 MEDIUM 5.0 CVE-2010-0696EPSS 28% Directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (Jw_allVideos) plugin 3.0 through 3.2 for Joomla! allows remo… Jw Allvideos Patch available Fix from $1,6002010-02-23 HIGH 7.5 CVE-2009-2395 SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands… Com K2 after 1.0.1 Fix from $1,9502009-07-09