VYPR

K2

by Joomla

CVEs (5)

  • CVE-2026-48945Jun 25, 2026
    risk 0.00cvss epss 0.00

    The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries//`, and only renames image files (gif/jpg/jpeg/png/webp) to safe names — non-image files (including `.php`) are extracted as-is and remain executable via direct HTTP access.

  • CVE-2026-48940Jun 25, 2026
    risk 0.00cvss epss 0.00

    A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `` tag; K2 stores it verbatim and renders it unescaped to any visitor of the article page.

  • CVE-2026-48946Jun 25, 2026
    risk 0.00cvss epss 0.00

    The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes them under the K2 web user. A K2 Author can upload a `shell.php`, then fetch `/media/k2/attachments/shell.php` and execute…

  • CVE-2026-48944Jun 25, 2026
    risk 0.00cvss epss 0.00

    The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::copy()`. `JPath::clean` does NOT strip `..`, and there is no allow-list of source paths. An Author can therefore copy…

  • CVE-2026-48943Jun 25, 2026
    risk 0.00cvss epss 0.00

    K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserForm=1` in a standard `com_users` `profile.save` POST, can write arbitrary values into the `notes`, `image`, and `plugins` columns of…