Verot maintains a focused file-upload handling library, class.upload.php, whose vulnerability footprint centers on a single, durable weakness class: unrestricted file uploads. This narrow but recurring exposure reflects the inherent risk of permitting arbitrary file types into systems without sufficient validation or containment mechanisms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Verot over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19576CRITICAL class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file | Dec 4, 2019 | 9.8 | 59 | NO | YES |
CVE-2019-19634CRITICAL class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous fil | Dec 17, 2019 | 9.8 | 34 | NO | NO |
CVE-2023-6551MEDIUM As a simple library, class.upload.php does not perform an in-depth check on uploaded files, allowing a stored XSS vulnerability when the default configuration is used.
Developer | Jan 4, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Verot.
Media articles that mention a CVE ID that affects a product developed by Verot — matched by CVE ID, not by vendor name.