Studio42

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    2
    Critical Level Threats
    3
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-81891

    elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)

    Last Modified: Sep 01, 2026
    Published: Aug 31, 2026

    CVE-2026-81890

    elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections

    Last Modified: Sep 01, 2026
    Published: Aug 31, 2026

    CVE-2026-81889

    elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback

    Last Modified: Sep 03, 2026
    Published: Aug 31, 2026

    CVE-2026-44521

    elFinder: SQL Injection MySQL Volume Driver (elFinderVolumeMySQL)

    Last Modified: May 30, 2026
    Published: May 27, 2026

    CVE-2026-41247

    elFinder: Command injection in resize background color parameter when using ImageMagick CLI

    Last Modified: Apr 28, 2026
    Published: Apr 23, 2026
    Items Per Page
    Studio42 Vulnerabilities & Security CVEs | CVE-DB