Extplorer records
18 published records for vendor extplorer.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 5.6%
- Pre-auth RCE
- 2
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-287 Improper Authentication1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2012-6710Weaponized | ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an actioextplorer · extplorer · CWE-287 | Critical9.8 | — | 25.0% | Oct 7, 2018 |
40Plan | CVE-2019-7305No exploit | eXtplorer exposes /usr and /etc/extplorer over HTTPextplorer · extplorer · CWE-200 | Critical9.8 | — | 1.8% | Apr 9, 2020 |
39Monitor | CVE-2023-54335No exploit | eXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)extplorer · extplorer · CWE-306 | Critical9.3 | — | 5.8% | Jan 13, 2026 |
39Monitor | CVE-2019-25097No exploit | soerennb eXtplorer Directory Content path traversalextplorer · extplorer · CWE-22 | Critical9.8 | — | 1.0% | Jan 5, 2023 |
39Monitor | CVE-2019-25098No exploit | soerennb eXtplorer Archive archive.php path traversalextplorer · extplorer · CWE-22 | Critical9.8 | — | 1.0% | Jan 5, 2023 |
36Monitor | CVE-2023-27842Proof of concept | Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code viaextplorer · extplorer · CWE-277 | High8.8 | — | 2.4% | Mar 21, 2023 |
35Monitor | CVE-2023-29657No exploit | eXtplorer 2.1.15 is vulnerable to Insecure Permissions.extplorer · extplorer · CWE-434 | High8.8 | — | 1.1% | May 12, 2023 |
34Monitor | CVE-2016-4313Proof of concept | Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitrary files via a ..extplorer · extplorer · CWE-22 | High7.8 | — | 8.7% | Apr 24, 2017 |
28Monitor | CVE-2017-12756No exploit | Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter.extplorer · extplorer · CWE-77 | High7.2 | — | 1.2% | Aug 9, 2017 |
27Monitor | CVE-2015-5660No exploit | Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary extplorer · extplorer · CWE-352 | Medium6.8 | — | 1.0% | Oct 15, 2015 |
27Monitor | CVE-2012-3362No exploit | Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of admextplorer · extplorer · CWE-352 | Medium6.8 | — | 0.9% | Jul 12, 2012 |
25Monitor | CVE-2008-4764Proof of concept | Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read aextplorer · com extplorer · CWE-22 | Medium5.0 | — | 16.5% | Oct 27, 2008 |
24Monitor | CVE-2019-25096No exploit | soerennb eXtplorer cross site scriptingextplorer · extplorer · CWE-79 | Medium6.1 | — | 0.6% | Jan 5, 2023 |
24Monitor | CVE-2023-40628No exploit | Extension - Extplorer.net - Reflected XSS in Extplorer component for Joomla 1.0.0-2.1.15extplorer · extplorer · CWE-79 | Medium6.1 | — | 0.4% | Dec 14, 2023 |
20Monitor | CVE-2025-13058No exploit | soerennb eXtplorer Filename cross site scriptingextplorer · extplorer · CWE-79 | Medium5.1 | — | 0.3% | Nov 12, 2025 |
17Monitor | CVE-2015-0896No exploit | Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer before 2.1.7 allow remote attackers to inject arbitrary web script or HTML extplorer · extplorer · CWE-79 | Medium4.3 | — | 1.2% | Mar 18, 2015 |
14Monitor | CVE-2012-3454No exploit | eXtplorer 2.1.0b6 uses world writable permissions for the /var/lib/extplorer/ftp_tmp directory, which allows local users to delete or overwrextplorer · extplorer · CWE-264 | Low3.6 | — | 0.3% | Aug 7, 2012 |
11Monitor | CVE-2013-5951No exploit | Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to injeextplorer · extplorer · CWE-79 | Low2.6 | — | 1.9% | Mar 25, 2014 |
- CVE-2012-671046Plan
ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an actio
CriticalCVSS 9.8WeaponizedEPSS 25%extplorer · extplorerOct 7, 2018
- CVE-2019-730540Plan
eXtplorer exposes /usr and /etc/extplorer over HTTP
CriticalCVSS 9.8No exploitEPSS 2%extplorer · extplorerApr 9, 2020
- CVE-2023-5433539Monitor
eXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)
CriticalCVSS 9.3No exploitEPSS 6%extplorer · extplorerJan 13, 2026
- CVE-2019-2509739Monitor
soerennb eXtplorer Directory Content path traversal
CriticalCVSS 9.8No exploitEPSS 1%extplorer · extplorerJan 5, 2023
- CVE-2019-2509839Monitor
soerennb eXtplorer Archive archive.php path traversal
CriticalCVSS 9.8No exploitEPSS 1%extplorer · extplorerJan 5, 2023
- CVE-2023-2784236Monitor
Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code via
HighCVSS 8.8Proof of conceptEPSS 2%extplorer · extplorerMar 21, 2023
- CVE-2023-2965735Monitor
eXtplorer 2.1.15 is vulnerable to Insecure Permissions.
HighCVSS 8.8No exploitEPSS 1%extplorer · extplorerMay 12, 2023
- CVE-2016-431334Monitor
Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitrary files via a ..
HighCVSS 7.8Proof of conceptEPSS 9%extplorer · extplorerApr 24, 2017
- CVE-2017-1275628Monitor
Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter.
HighCVSS 7.2No exploitEPSS 1%extplorer · extplorerAug 9, 2017
- CVE-2015-566027Monitor
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary
MediumCVSS 6.8No exploitEPSS 1%extplorer · extplorerOct 15, 2015
- CVE-2012-336227Monitor
Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of adm
MediumCVSS 6.8No exploitEPSS 1%extplorer · extplorerJul 12, 2012
- CVE-2008-476425Monitor
Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read a
MediumCVSS 5.0Proof of conceptEPSS 17%extplorer · com extplorerOct 27, 2008
- CVE-2019-2509624Monitor
soerennb eXtplorer cross site scripting
MediumCVSS 6.1No exploitEPSS 1%extplorer · extplorerJan 5, 2023
- CVE-2023-4062824Monitor
Extension - Extplorer.net - Reflected XSS in Extplorer component for Joomla 1.0.0-2.1.15
MediumCVSS 6.1No exploitEPSS 0%extplorer · extplorerDec 14, 2023
- CVE-2025-1305820Monitor
soerennb eXtplorer Filename cross site scripting
MediumCVSS 5.1No exploitEPSS 0%extplorer · extplorerNov 12, 2025
- CVE-2015-089617Monitor
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer before 2.1.7 allow remote attackers to inject arbitrary web script or HTML
MediumCVSS 4.3No exploitEPSS 1%extplorer · extplorerMar 18, 2015
- CVE-2012-345414Monitor
eXtplorer 2.1.0b6 uses world writable permissions for the /var/lib/extplorer/ftp_tmp directory, which allows local users to delete or overwr
LowCVSS 3.6No exploitEPSS 0%extplorer · extplorerAug 7, 2012
- CVE-2013-595111Monitor
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inje
LowCVSS 2.6No exploitEPSS 2%extplorer · extplorerMar 25, 2014