Каталог CVE

Расширение: Joomlaworks K2

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 5

Расширение: Joomlaworks K2
Средняя CVSS 6.5

CVE-2026-48943

РасширениеJoomlaworks K2
Разработчикgetk2

K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserForm=1` in a standard `com_users` `profile.sa…

25.06.2026 Активна
Низкая CVSS 3.4

CVE-2026-48940

РасширениеJoomlaworks K2
Разработчикgetk2

A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; K2 stores it verbatim and renders it u…

25.06.2026 Активна
Критическая CVSS 9.8

CVE-2019-19634

РасширениеVerot Project Verot
Разработчикgithub

class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensi…

17.12.2019
Критическая CVSS 9.8

CVE-2019-19576

РасширениеVerot Project Verot
Разработчикpacketstormsecurity

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensio…

04.12.2019
Высокая CVSS 7.5

CVE-2018-7482

РасширениеJoomlaworks K2
Разработчикexploit-db

The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demonstrated by a view=media&task=connector&cm…

28.02.2018