CVE-2019-19634: Joomlaworks k2

Critical severity, CVSS 9.8. EPSS: 4.2% chance of exploitation in the next 30 days.

class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.

Affected products

  • Joomlaworks k2: up to and including 2.10.1
  • Verot Project Verot: before 1.0.3 (fixed in 1.0.3); from 2.0.0, before 2.0.4 (fixed in 2.0.4)

Published 2019-12-17. Last modified 2026-06-26.