Joomlaworks develops a narrow portfolio of Joomla extensions and plugins, including the widely embedded K2 content component and related multimedia modules, that extend the functionality of Joomla-based websites. The recurring vulnerability signal centers on application-layer input-handling flaws, particularly path-traversal and SQL-injection weaknesses, which are characteristic of web-component development and the integration demands of plugin architectures; current exposure counts and severity profiles are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joomlaworks over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19576CRITICAL class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file | Dec 4, 2019 | 9.8 | 59 | NO | YES |
CVE-2010-0696MEDIUM Directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (Jw_allVideos) plugin 3.0 through 3.2 for Joomla! allows remote attackers to read arbitrary | Feb 23, 2010 | 5.0 | 46 | NO | YES |
CVE-2019-19634CRITICAL class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous fil | Dec 17, 2019 | 9.8 | 34 | NO | NO |
CVE-2009-2395HIGH SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter in | Jul 9, 2009 | 7.5 | 29 | NO | YES |
CVE-2026-48946MEDIUM The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes them under the K2 web user. A K2 | Jun 25, 2026 | 6.3 | 27 | NO | NO |
CVE-2026-48944MEDIUM The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::copy()`. `JPath::clean` does NOT | Jun 25, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-48943MEDIUM K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserForm=1` in a standard `com_users` `p | Jun 25, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-48941MEDIUM The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` call under `/media/k2/galleries/ | Jun 25, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-48942MEDIUM K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping. | Jun 25, 2026 | 6.1 | 26 | NO | NO |
CVE-2026-48945MEDIUM The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only renames image files (gif/jpg/jpeg/png/webp) to safe names — no | Jun 25, 2026 | 5.3 | 25 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joomlaworks.
Media articles that mention a CVE ID that affects a product developed by Joomlaworks — matched by CVE ID, not by vendor name.