Known Vulnerabilities for Elfinder by Std42
Listed below are 10 of the newest known vulnerabilities associated with "Elfinder" by "Std42".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-44260 json | efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the |
Not Provided | 2026-05-12 | 2026-05-13 |
| CVE-2026-41247 json | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a ... | Not Provided | 2026-04-23 | 2026-04-25 |
| CVE-2026-34415 json | Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connecto... | Not Provided | 2026-04-22 | 2026-04-24 |
| CVE-2026-34414 json | Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability in the elFinder connector end... | Not Provided | 2026-04-22 | 2026-04-24 |
| CVE-2026-34413 json | Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endp... | Not Provided | 2026-04-22 | 2026-04-24 |
| CVE-2023-35840 json | _joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDr... | 6.5 - MEDIUM | 2023-06-19 | 2023-06-26 |
| CVE-2022-27115 json | In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file up... | 9.8 - CRITICAL | 2022-04-11 | 2022-04-15 |
| CVE-2022-26960 json | connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote atta... | 9.1 - CRITICAL | 2022-03-21 | 2022-06-30 |
| CVE-2021-45919 json | Studio 42 elFinder through 2.1.31 allows XSS via an SVG document. | 5.4 - MEDIUM | 2022-02-08 | 2022-02-11 |
| CVE-2021-43421 json | A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote mal... | 9.8 - CRITICAL | 2022-04-07 | 2022-04-13 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Std42 | Elfinder | 2.1.9 | |||
| Application | Std42 | Elfinder | 2.1.8 | |||
| Application | Std42 | Elfinder | 2.1.7 | |||
| Application | Std42 | Elfinder | 2.1.6 | |||
| Application | Std42 | Elfinder | 2.1.5 | |||
| Application | Std42 | Elfinder | 2.1.49 | |||
| Application | Std42 | Elfinder | 2.1.48 | |||
| Application | Std42 | Elfinder | 2.1.47 | |||
| Application | Std42 | Elfinder | 2.1.46 | |||
| Application | Std42 | Elfinder | 2.1.45 | |||
| Application | Std42 | Elfinder | 2.1.44 | |||
| Application | Std42 | Elfinder | 2.1.43 | |||
| Application | Std42 | Elfinder | 2.1.42 | |||
| Application | Std42 | Elfinder | 2.1.41 | |||
| Application | Std42 | Elfinder | 2.1.40 | |||
| Application | Std42 | Elfinder | 2.1.4 | |||
| Application | Std42 | Elfinder | 2.1.39 | |||
| Application | Std42 | Elfinder | 2.1.38 | |||
| Application | Std42 | Elfinder | 2.1.37 | |||
| Application | Std42 | Elfinder | 2.1.36 |