Joomla K2 component version 2.9.0 suffers from database disclosure and remote SQL injection vulnerabilities.