K2

Vendor:

First CVE: Feb 28, 2018 · Active for 8 years

10
Total CVEs
More Total CVEs than 88% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact K2 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 28, 2018
8 years ago
Most Recent CVE
Jun 25, 2026
31 days ago

CVE Severity & Scoring

K210 CVEs
All CVEs352,719 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (80.0%)
Unknown0 (0.0%)
Required2 (20.0%)
Privileges Required
Low2 (20.0%)
High1 (10.0%)
None7 (70.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file
Dec 4, 20199.859NOYES
class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous fil
Dec 17, 20199.834NONO
The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes them under the K2 web user. A K2
Jun 25, 20266.327NONO
The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::copy()`. `JPath::clean` does NOT
Jun 25, 20266.527NONO
K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserForm=1` in a standard `com_users` `p
Jun 25, 20266.527NONO
The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` call under `/media/k2/galleries/
Jun 25, 20266.527NONO
K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping.
Jun 25, 20266.126NONO
The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only renames image files (gif/jpg/jpeg/png/webp) to safe names — no
Jun 25, 20265.325NONO
The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demonstrated by a view=media&task=con
Feb 28, 20187.525NONO
A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; K2 stores it verbatim and ren
Jun 25, 20263.421NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For K2

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.8.017.52.4%00