Elfinder
This hub aggregates every CVE we track for Elfinder, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
18
CVEs tracked
10
Critical
3
High
0
In CISA KEV
Severity distribution
CRITICAL10MEDIUM5HIGH3
Monthly trend
0
0
2
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
1
0
0
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting Elfinder.
- CVE-2026-44521elFinder: SQL Injection MySQL Volume Driver (elFinderVolumeMySQL)8.8
- CVE-2026-41247elFinder: Command injection in resize background color parameter when using ImageMagick CLI9.8
- CVE-2023-52045Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.6.1
- CVE-2023-52044Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.9.8
- CVE-2024-38909Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform ...9.8
- CVE-2023-35840_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.6.5
- CVE-2022-27115In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.9.8
- CVE-2021-43421A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code.9.8
- CVE-2022-26960connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document r...9.1
- CVE-2021-45919Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.5.4
- CVE-2021-32682Multiple vulnerabilities leading to RCE9.8
- CVE-2021-23394Remote Code Execution (RCE)8.1
- CVE-2019-9194elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.9.8
- CVE-2019-6257A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network resources. This occurs in get_remote_contents() i...7.7
- CVE-2019-5884php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set.5.9
Product normalization is registry-driven with AI assist and human review. How it works