CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2026-41247 HIGH

elFinder: Command injection in resize background color parameter when using ImageMagick CLI

CVSS 8.9 EPSS 2.65% Apr 23, 2026
CVE-2023-52045 MEDIUM

Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.

CVSS 6.1 EPSS 0.27% Oct 31, 2024
CVE-2023-52044 CRITICAL

Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.

CVSS 9.8 EPSS 0.79% Oct 31, 2024
CVE-2024-38909 HIGH

Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrar…

CVSS 8.1 EPSS 0.48% Jul 30, 2024
CVE-2023-35840 HIGH

_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.

CVSS 7.5 EPSS 1.94% Jun 19, 2023
CVE-2022-27115 CRITICAL

In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.

CVSS 9.8 EPSS 28.59% Apr 11, 2022
CVE-2021-43421 CRITICAL

A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary fi…

CVSS 9.8 EPSS 42.78% Apr 7, 2022
CVE-2022-26960 CRITICAL

connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse f…

CVSS 9.1 EPSS 50.99% Mar 21, 2022
CVE-2021-45919 MEDIUM

Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.

CVSS 5.4 EPSS 0.63% Feb 8, 2022
CVE-2021-32682 CRITICAL

Multiple vulnerabilities leading to RCE

CVSS 9.8 EPSS 69.93% Jun 14, 2021
CVE-2021-23394 CRITICAL

Remote Code Execution (RCE)

CVSS 9.8 EPSS 18.93% Jun 13, 2021
CVE-2019-9194 CRITICAL

elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.

CVSS 9.8 EPSS 96.73% Feb 26, 2019
CVE-2019-6257 HIGH

A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network resources.…

CVSS 7.7 EPSS 1.10% Jan 14, 2019
CVE-2019-5884 MEDIUM

php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set.

CVSS 5.9 EPSS 1.27% Jan 10, 2019
CVE-2018-9110 CRITICAL

Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to do…

CVSS 9.1 EPSS 2.88% Mar 28, 2018
CVE-2018-9109 CRITICAL

Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to do…

CVSS 9.1 EPSS 2.94% Mar 28, 2018

Showing 1 to 16 CVEs · page 1