CVE-2019-19576: Joomlaworks k2

Critical severity, CVSS 9.8. EPSS: 26.4% chance of exploitation in the next 30 days.

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.

Affected products

  • Joomlaworks k2: up to and including 2.10.1
  • Verot Project Verot: before 1.0.3 (fixed in 1.0.3); from 2.0.0, before 2.0.4 (fixed in 2.0.4)

Published 2019-12-04. Last modified 2026-06-26.