Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-41247 elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulner… Elfinder 2.1.67+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2023-52044 Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension. Elfinder No fix yet Fix from $2,3002024-10-31 MEDIUM 6.1 CVE-2023-52045 Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability. Elfinder No fix yet Fix from $1,6002024-10-31 CRITICAL 9.8 CVE-2024-38909 Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows a… Elfinder Mitigation only Fix from $2,3002024-07-30 MEDIUM 6.5 CVE-2023-35840 _joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector. Elfinder 2.1.62+ Fix from $1,6002023-06-19 CRITICAL 9.8 CVE-2022-27115EPSS 29% In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload. Elfinder Patch available Fix from $2,3002022-04-11 CRITICAL 9.8 CVE-2021-43421EPSS 43% A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload ar… Elfinder after 2.1.59 Fix from $2,3002022-04-07 CRITICAL 9.1 CVE-2022-26960EPSS 51% connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, an… Elfinder 2.1.61+ Fix from $2,3002022-03-21 MEDIUM 5.4 CVE-2021-45919 Studio 42 elFinder through 2.1.31 allows XSS via an SVG document. Elfinder after 2.1.31 Fix from $1,6002022-02-08 CRITICAL 9.8 CVE-2021-32682EPSS 70% elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnera… Elfinder 2.1.59+ Fix from $2,3002021-06-14 CRITICAL 9.8 CVE-2021-23394EPSS 19% The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only… Elfinder 2.1.58+ Fix from $2,3002021-06-13 CRITICAL 9.8 CVE-2019-9194EPSS 97% elFinder before 2.1.48 has a command injection vulnerability in the PHP connector. Elfinder 2.1.48+ Fix from $2,3002019-02-26 HIGH 7.7 CVE-2019-6257 A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network r… Elfinder 2.1.46+ Fix from $1,9502019-01-14 MEDIUM 5.9 CVE-2019-5884 php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set. Elfinder 2.1.45+ Fix from $1,6002019-01-10 CRITICAL 9.1 CVE-2018-9110 Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote atta… Elfinder 2.1.37+ Fix from $2,3002018-03-28 CRITICAL 9.1 CVE-2018-9109 Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote atta… Elfinder 2.1.36+ Fix from $2,3002018-03-28