Joomlaworks
7 known vulnerabilities
Top Products
The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php ma
The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only re
The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SI
K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by inc
K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both
The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to ad
A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field
Frequently Asked Questions
How many CVEs affect Joomlaworks?
Joomlaworks has 7 CVE records in our database, including 0 critical and 0 high severity vulnerabilities.
What are the most severe Joomlaworks vulnerabilities?
Joomlaworks has 0 critical severity (CVSS 9.0+) and 0 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Joomlaworks vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Joomlaworks products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Joomlaworks Vulnerabilities
CyberStrike scans your infrastructure for Joomlaworks vulnerabilities and provides real-time remediation guidance.
Get Started