Skip to content
Noroxi

Extplorer records

18 published records for vendor extplorer.

All records

18 records
  • ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an actio

    CriticalCVSS 9.8WeaponizedEPSS 25%

    extplorer · extplorerOct 7, 2018

  • eXtplorer exposes /usr and /etc/extplorer over HTTP

    CriticalCVSS 9.8No exploitEPSS 2%

    extplorer · extplorerApr 9, 2020

  • eXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)

    CriticalCVSS 9.3No exploitEPSS 6%

    extplorer · extplorerJan 13, 2026

  • soerennb eXtplorer Directory Content path traversal

    CriticalCVSS 9.8No exploitEPSS 1%

    extplorer · extplorerJan 5, 2023

  • soerennb eXtplorer Archive archive.php path traversal

    CriticalCVSS 9.8No exploitEPSS 1%

    extplorer · extplorerJan 5, 2023

  • Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code via

    HighCVSS 8.8Proof of conceptEPSS 2%

    extplorer · extplorerMar 21, 2023

  • eXtplorer 2.1.15 is vulnerable to Insecure Permissions.

    HighCVSS 8.8No exploitEPSS 1%

    extplorer · extplorerMay 12, 2023

  • CVE-2016-4313
    34Monitor

    Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitrary files via a ..

    HighCVSS 7.8Proof of conceptEPSS 9%

    extplorer · extplorerApr 24, 2017

  • Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter.

    HighCVSS 7.2No exploitEPSS 1%

    extplorer · extplorerAug 9, 2017

  • CVE-2015-5660
    27Monitor

    Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary

    MediumCVSS 6.8No exploitEPSS 1%

    extplorer · extplorerOct 15, 2015

  • CVE-2012-3362
    27Monitor

    Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of adm

    MediumCVSS 6.8No exploitEPSS 1%

    extplorer · extplorerJul 12, 2012

  • CVE-2008-4764
    25Monitor

    Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read a

    MediumCVSS 5.0Proof of conceptEPSS 17%

    extplorer · com extplorerOct 27, 2008

  • soerennb eXtplorer cross site scripting

    MediumCVSS 6.1No exploitEPSS 1%

    extplorer · extplorerJan 5, 2023

  • Extension - Extplorer.net - Reflected XSS in Extplorer component for Joomla 1.0.0-2.1.15

    MediumCVSS 6.1No exploitEPSS 0%

    extplorer · extplorerDec 14, 2023

  • soerennb eXtplorer Filename cross site scripting

    MediumCVSS 5.1No exploitEPSS 0%

    extplorer · extplorerNov 12, 2025

  • CVE-2015-0896
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer before 2.1.7 allow remote attackers to inject arbitrary web script or HTML

    MediumCVSS 4.3No exploitEPSS 1%

    extplorer · extplorerMar 18, 2015

  • CVE-2012-3454
    14Monitor

    eXtplorer 2.1.0b6 uses world writable permissions for the /var/lib/extplorer/ftp_tmp directory, which allows local users to delete or overwr

    LowCVSS 3.6No exploitEPSS 0%

    extplorer · extplorerAug 7, 2012

  • CVE-2013-5951
    11Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inje

    LowCVSS 2.6No exploitEPSS 2%

    extplorer · extplorerMar 25, 2014