← Vulnerability feed

Vulnerability record · CVE-2019-19576 · published 4 December 2019

CVE-2019-19576: Verot project verot unrestricted file upload vulnerability

Verot Project · Verot

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.

9.8 CVSS 3.1 Critical EPSS 26% · top 2.1% CWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score, v2 7.5
26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
20References, 4 tagged exploit
26 Jun 2026Last modified by NVD

Description

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/155577/Verot-2.0.3-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
https://github.com/getk2/k2/commit/d1344706c4b74c2ae7659b286b5a066117155124 PatchThird Party Advisory
https://github.com/jra89/CVE-2019-19576 ExploitThird Party Advisory
https://github.com/verot/class.upload.php/commit/5a7505ddec956fdc9e9c071ae5089865559174f1 PatchThird Party Advisory
https://github.com/verot/class.upload.php/commit/db1b4fe50c1754696970d8b437f07e7b94a7ebf2 PatchThird Party Advisory
https://github.com/verot/class.upload.php/compare/1.0.2...1.0.3 PatchThird Party Advisory
https://github.com/verot/class.upload.php/compare/2.0.3...2.0.4 PatchThird Party Advisory
https://medium.com/%40jra8908/cve-2019-19576-e9da712b779
https://www.verot.net Product
https://www.verot.net/php_class_upload.htm Vendor Advisory
http://packetstormsecurity.com/files/155577/Verot-2.0.3-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
https://github.com/getk2/k2/commit/d1344706c4b74c2ae7659b286b5a066117155124 PatchThird Party Advisory
https://github.com/jra89/CVE-2019-19576 ExploitThird Party Advisory
https://github.com/verot/class.upload.php/commit/5a7505ddec956fdc9e9c071ae5089865559174f1 PatchThird Party Advisory
https://github.com/verot/class.upload.php/commit/db1b4fe50c1754696970d8b437f07e7b94a7ebf2 PatchThird Party Advisory
https://github.com/verot/class.upload.php/compare/1.0.2...1.0.3 PatchThird Party Advisory
https://github.com/verot/class.upload.php/compare/2.0.3...2.0.4 PatchThird Party Advisory
https://medium.com/%40jra8908/cve-2019-19576-e9da712b779
https://www.verot.net Product
https://www.verot.net/php_class_upload.htm Vendor Advisory

Track CVE-2019-19576 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-19634Verot project verot unrestricted file upload vulnerabilityclass.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .ph…EPSS 4.2%7.5CVE-2018-7482Joomlaworks k2 path traversal vulnerabilityThe K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demons…EPSS 2.3%6.5CVE-2026-48941Joomlaworks k2 missing authorization vulnerabilityThe K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` c…EPSS 0.27%6.5CVE-2026-48943Joomlaworks k2 mass assignment vulnerabilityK2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserForm=…EPSS 0.30%6.5CVE-2026-48944Joomlaworks k2 path traversal vulnerabilityThe K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::co…EPSS 0.44%6.3CVE-2026-48946Joomlaworks k2 unrestricted file upload vulnerabilityThe K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes t…EPSS 0.28%6.1CVE-2026-48942Joomlaworks k2 cross-site scripting vulnerabilityK2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping.EPSS 0.25%5.3CVE-2026-48945Joomlaworks k2 unrestricted file upload vulnerabilityThe K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only renames image files (gif/jpg/jp…EPSS 0.33%

Source: NIST National Vulnerability Database (record CVE-2019-19576), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.