Known Vulnerabilities for products from Extplorer

Listed below are 15 of the newest known vulnerabilities associated with the vendor "Extplorer".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2023-29657 json eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing php ... 8.8 - HIGH 2023-05-12 2023-05-22
CVE-2023-27842 json Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arb... 8.8 - HIGH 2023-03-21 2023-03-27
CVE-2019-25098 json A vulnerability was found in soerennb eXtplorer up to 2.1.12. It has been classified as critical. This affects an unknown par... 9.8 - CRITICAL 2023-01-05 2023-11-07
CVE-2019-25097 json A vulnerability was found in soerennb eXtplorer up to 2.1.12 and classified as critical. Affected by this issue is some unkno... 9.8 - CRITICAL 2023-01-05 2023-11-07
CVE-2019-25096 json A vulnerability has been found in soerennb eXtplorer up to 2.1.12 and classified as problematic. Affected by this vulnerabili... 6.1 - MEDIUM 2023-01-05 2023-11-07
CVE-2019-7305 json Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over ... 9.8 - CRITICAL 2020-04-10 2021-09-13
CVE-2017-12756 json Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfil... 7.2 - HIGH 2017-08-09 2017-08-20
CVE-2016-4313 json Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitrary fi... Not Provided 2017-04-24 2025-04-20
CVE-2015-5660 json Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authenticatio... Not Provided 2015-10-16 2026-05-06
CVE-2015-0896 json Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer before 2.1.7 allow remote attackers to inject arbitrary web ... Not Provided 2015-03-18 2026-05-06
CVE-2013-5951 json Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote at... Not Provided 2014-03-25 2026-05-06
CVE-2012-6710 json ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty arr... 9.8 - CRITICAL 2018-10-07 2019-01-08
CVE-2012-3454 json eXtplorer 2.1.0b6 uses world writable permissions for the /var/lib/extplorer/ftp_tmp directory, which allows local users to d... Not Provided 2012-08-07 2026-04-29
CVE-2012-3362 json Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authen... Not Provided 2012-07-12 2026-04-29
CVE-2008-4764 json Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote atta... Not Provided 2008-10-28 2026-04-23

Known software with vulnerabilities from Extplorer

Type Vendor Product Version
ApplicationExtplorerCom Extplorer2.0.0
ApplicationExtplorerExtplorer2.0.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report