Elfinder
This hub aggregates every CVE we track for Elfinder, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
21
CVEs tracked
10
Critical
5
High
0
In CISA KEV
Severity distribution
CRITICAL10MEDIUM6HIGH5
Monthly trend
2
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
1
0
0
3
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Elfinder.
- CVE-2026-81891elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)8.1
- CVE-2026-81890elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections5.4
- CVE-2026-81889elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback8.6
- CVE-2026-44521elFinder: SQL Injection MySQL Volume Driver (elFinderVolumeMySQL)8.8
- CVE-2026-41247elFinder: Command injection in resize background color parameter when using ImageMagick CLI9.8
- CVE-2023-52045Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.6.1
- CVE-2023-52044Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.9.8
- CVE-2024-38909Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform ...9.8
- CVE-2023-35840_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.6.5
- CVE-2022-27115In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.9.8
- CVE-2021-43421A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code.9.8
- CVE-2022-26960connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document r...9.1
- CVE-2021-45919Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.5.4
- CVE-2021-32682Multiple vulnerabilities leading to RCE9.8
- CVE-2021-23394Remote Code Execution (RCE)8.1
Product normalization is registry-driven with AI assist and human review. How it works