Studio-42/elfinder
This hub aggregates every CVE we track for Studio-42/elfinder, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
13
CVEs tracked
8
Critical
2
High
0
In CISA KEV
Severity distribution
CRITICAL8MEDIUM3HIGH2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-082026-07
Latest CVEs
The 13 most recently published vulnerabilities affecting Studio-42/elfinder.
- CVE-2024-38909Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform ...9.8
- CVE-2023-35840_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.6.5
- CVE-2022-27115In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.9.8
- CVE-2021-43421A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code.9.8
- CVE-2022-26960connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document r...9.1
- CVE-2021-45919Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.5.4
- CVE-2021-32682Multiple vulnerabilities leading to RCE9.8
- CVE-2021-23394Remote Code Execution (RCE)8.1
- CVE-2019-9194elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.9.8
- CVE-2019-6257A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network resources. This occurs in get_remote_contents() i...7.7
- CVE-2019-5884php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set.5.9
- CVE-2018-9110Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessible by the web ser...9.1
- CVE-2018-9109Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessible by the web ser...9.1
Product normalization is registry-driven with AI assist and human review. How it works