Std42 / Elfinder
16 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-41247 | elFinder: Command injection in resize background color parameter when using ImageMagick CLI | HIGH | 8.9 | Apr 23, 2026 |
| CVE-2023-52045 | Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability. | MEDIUM | 6.1 | Oct 31, 2024 |
| CVE-2023-52044 | Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension. | CRITICAL | 9.8 | Oct 31, 2024 |
| CVE-2024-38909 | Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrar… | HIGH | 8.1 | Jul 30, 2024 |
| CVE-2023-35840 | _joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector. | HIGH | 7.5 | Jun 19, 2023 |
| CVE-2022-27115 | In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload. | CRITICAL | 9.8 | Apr 11, 2022 |
| CVE-2021-43421 | A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary fi… | CRITICAL | 9.8 | Apr 7, 2022 |
| CVE-2022-26960 | connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse f… | CRITICAL | 9.1 | Mar 21, 2022 |
| CVE-2021-45919 | Studio 42 elFinder through 2.1.31 allows XSS via an SVG document. | MEDIUM | 5.4 | Feb 8, 2022 |
| CVE-2021-32682 | Multiple vulnerabilities leading to RCE | CRITICAL | 9.8 | Jun 14, 2021 |
| CVE-2021-23394 | Remote Code Execution (RCE) | CRITICAL | 9.8 | Jun 13, 2021 |
| CVE-2019-9194 | elFinder before 2.1.48 has a command injection vulnerability in the PHP connector. | CRITICAL | 9.8 | Feb 26, 2019 |
| CVE-2019-6257 | A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network resources.… | HIGH | 7.7 | Jan 14, 2019 |
| CVE-2019-5884 | php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set. | MEDIUM | 5.9 | Jan 10, 2019 |
| CVE-2018-9110 | Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to do… | CRITICAL | 9.1 | Mar 28, 2018 |
| CVE-2018-9109 | Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to do… | CRITICAL | 9.1 | Mar 28, 2018 |
Showing 1 to 16 of 16 CVEs