Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2026-41247
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulner…
Elfinder
2.1.67+
CRITICAL 9.8
CVE-2023-52044
Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.
Elfinder
No fix yet
MEDIUM 6.1
CVE-2023-52045
Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.
Elfinder
No fix yet
CRITICAL 9.8
CVE-2024-38909
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows a…
Elfinder
Mitigation only
MEDIUM 6.5
CVE-2023-35840
_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.
Elfinder
2.1.62+
CRITICAL 9.8
CVE-2022-27115EPSS 29%
In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.
Elfinder
Patch available
CRITICAL 9.8
CVE-2021-43421EPSS 43%
A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload ar…
Elfinder
after 2.1.59
CRITICAL 9.1
CVE-2022-26960EPSS 51%
connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, an…
Elfinder
2.1.61+
MEDIUM 5.4
CVE-2021-45919
Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.
Elfinder
after 2.1.31
CRITICAL 9.8
CVE-2021-32682EPSS 70%
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnera…
Elfinder
2.1.59+
CRITICAL 9.8
CVE-2021-23394EPSS 19%
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only…
Elfinder
2.1.58+
CRITICAL 9.8
CVE-2019-9194EPSS 97%
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
Elfinder
2.1.48+
HIGH 7.7
CVE-2019-6257
A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network r…
Elfinder
2.1.46+
MEDIUM 5.9
CVE-2019-5884
php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set.
Elfinder
2.1.45+
CRITICAL 9.1
CVE-2018-9110
Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote atta…
Elfinder
2.1.37+
CRITICAL 9.1
CVE-2018-9109
Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote atta…
Elfinder
2.1.36+