Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Elfinder CRITICAL 9.8
CVE-2026-41247

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulner…

Fix: 2.1.67+
Fix from $2,300 2026-04-23
Elfinder CRITICAL 9.8
CVE-2023-52044

Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.

No fix yet
Fix from $2,300 2024-10-31
Elfinder MEDIUM 6.1
CVE-2023-52045

Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.

No fix yet
Fix from $1,600 2024-10-31
Elfinder CRITICAL 9.8
CVE-2024-38909

Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows a…

Mitigation only
Fix from $2,300 2024-07-30
Elfinder MEDIUM 6.5
CVE-2023-35840

_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.

Fix: 2.1.62+
Fix from $1,600 2023-06-19
Elfinder CRITICAL 9.8
CVE-2022-27115EPSS 29%

In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.

Patch available
Fix from $2,300 2022-04-11
Elfinder CRITICAL 9.8
CVE-2021-43421EPSS 43%

A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload ar…

Fix: after 2.1.59
Fix from $2,300 2022-04-07
Elfinder CRITICAL 9.1
CVE-2022-26960EPSS 51%

connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, an…

Fix: 2.1.61+
Fix from $2,300 2022-03-21
Elfinder MEDIUM 5.4
CVE-2021-45919

Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.

Fix: after 2.1.31
Fix from $1,600 2022-02-08
Elfinder CRITICAL 9.8
CVE-2021-32682EPSS 70%

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnera…

Fix: 2.1.59+
Fix from $2,300 2021-06-14
Elfinder CRITICAL 9.8
CVE-2021-23394EPSS 19%

The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only…

Fix: 2.1.58+
Fix from $2,300 2021-06-13
Elfinder CRITICAL 9.8
CVE-2019-9194EPSS 97%

elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.

Fix: 2.1.48+
Fix from $2,300 2019-02-26
Elfinder HIGH 7.7
CVE-2019-6257

A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network r…

Fix: 2.1.46+
Fix from $1,950 2019-01-14
Elfinder MEDIUM 5.9
CVE-2019-5884

php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set.

Fix: 2.1.45+
Fix from $1,600 2019-01-10
Elfinder CRITICAL 9.1
CVE-2018-9110

Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote atta…

Fix: 2.1.37+
Fix from $2,300 2018-03-28
Elfinder CRITICAL 9.1
CVE-2018-9109

Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote atta…

Fix: 2.1.36+
Fix from $2,300 2018-03-28