Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Joomlaworks

First CVE: Jul 9, 2009Active for: 17 yearsTotal CVEs: 12
33.5
VTI Score
Medium

Joomlaworks develops a narrow portfolio of Joomla extensions and plugins, including the widely embedded K2 content component and related multimedia modules, that extend the functionality of Joomla-based websites. The recurring vulnerability signal centers on application-layer input-handling flaws, particularly path-traversal and SQL-injection weaknesses, which are characteristic of web-component development and the integration demands of plugin architectures; current exposure counts and severity profiles are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Joomlaworks over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 9, 2009
17 years ago
Most Recent CVE
Jun 25, 2026
29 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-19576CRITICAL
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file
Dec 4, 20199.859NOYES
CVE-2010-0696MEDIUM
Directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (Jw_allVideos) plugin 3.0 through 3.2 for Joomla! allows remote attackers to read arbitrary
Feb 23, 20105.046NOYES
CVE-2019-19634CRITICAL
class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous fil
Dec 17, 20199.834NONO
CVE-2009-2395HIGH
SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter in
Jul 9, 20097.529NOYES
CVE-2026-48946MEDIUM
The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes them under the K2 web user. A K2
Jun 25, 20266.327NONO
CVE-2026-48944MEDIUM
The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::copy()`. `JPath::clean` does NOT
Jun 25, 20266.527NONO
CVE-2026-48943MEDIUM
K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserForm=1` in a standard `com_users` `p
Jun 25, 20266.527NONO
CVE-2026-48941MEDIUM
The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` call under `/media/k2/galleries/
Jun 25, 20266.527NONO
CVE-2026-48942MEDIUM
K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping.
Jun 25, 20266.126NONO
CVE-2026-48945MEDIUM
The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only renames image files (gif/jpg/jpeg/png/webp) to safe names — no
Jun 25, 20265.325NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
8%
58%
17%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (83.3%)
Unknown2 (16.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (83.3%)
High0 (0.0%)
Unknown2 (16.7%)
User Interaction
None8 (66.7%)
Unknown2 (16.7%)
Required2 (16.7%)
Privileges Required
Low2 (16.7%)
High1 (8.3%)
None7 (58.3%)
Unknown2 (16.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
8.3% of CVEs· 96th percentile
ExploitDB
3 CVEs
25.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Joomlaworks.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Joomlaworks — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Joomlaworks's Products

View all 2 CNAs →

Top CWEs