Products: 1
    Vulnerabilities: 16
    Known Exploited: 0
    10
    Critical Level Threats
    2
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-41247

    elFinder: Command injection in resize background color parameter when using ImageMagick CLI

    Last Modified: Apr 28, 2026
    Published: Apr 23, 2026

    CVE-2023-52045

    Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.

    Last Modified: Apr 17, 2025
    Published: Oct 31, 2024

    CVE-2023-52044

    Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.

    Last Modified: Apr 17, 2025
    Published: Oct 31, 2024

    CVE-2024-38909

    Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.

    Last Modified: Apr 28, 2025
    Published: Jul 30, 2024

    CVE-2023-35840

    _joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.

    Last Modified: Dec 12, 2024
    Published: Jun 19, 2023
    Items Per Page
    Std42 Vulnerabilities & Security CVEs | CVE-DB