K2
Vendor:
First CVE: Feb 28, 2018 · Active for 8 years
10
Total CVEs
More Total CVEs than 88% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact K2 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 28, 2018
8 years ago
Most Recent CVE
Jun 25, 2026
31 days ago
CVE Severity & Scoring
K210 CVEs
10%
60%
10%
20%
All CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (80.0%)
Unknown0 (0.0%)
Required2 (20.0%)
Privileges Required
Low2 (20.0%)
High1 (10.0%)
None7 (70.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19576CRITICAL class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file | Dec 4, 2019 | 9.8 | 59 | NO | YES |
CVE-2019-19634CRITICAL class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous fil | Dec 17, 2019 | 9.8 | 34 | NO | NO |
CVE-2026-48946MEDIUM The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes them under the K2 web user. A K2 | Jun 25, 2026 | 6.3 | 27 | NO | NO |
CVE-2026-48944MEDIUM The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::copy()`. `JPath::clean` does NOT | Jun 25, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-48943MEDIUM K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserForm=1` in a standard `com_users` `p | Jun 25, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-48941MEDIUM The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` call under `/media/k2/galleries/ | Jun 25, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-48942MEDIUM K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping. | Jun 25, 2026 | 6.1 | 26 | NO | NO |
CVE-2026-48945MEDIUM The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only renames image files (gif/jpg/jpeg/png/webp) to safe names — no | Jun 25, 2026 | 5.3 | 25 | NO | NO |
CVE-2018-7482HIGH The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demonstrated by a view=media&task=con | Feb 28, 2018 | 7.5 | 25 | NO | NO |
A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; K2 stores it verbatim and ren | Jun 25, 2026 | 3.4 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For K2
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.8.0 | 1 | 7.5 | 2.4% | 0 | 0 |