Known Vulnerabilities for Cw Article Attachments Pro by Cwjoomla
Listed below are 1 of the newest known vulnerabilities associated with "Cw Article Attachments Pro" by "Cwjoomla".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-48946 json | The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches... | Not Provided | 2026-06-25 | 2026-06-28 |
| CVE-2026-48944 json | The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` ... | Not Provided | 2026-06-25 | 2026-06-28 |
| CVE-2018-14592 json | The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joo... | 9.8 - CRITICAL | 2018-09-20 | 2018-11-09 |