std42 records
16 published records for vendor std42.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 12.5%
- Pre-auth RCE
- 7
- With a fix record
- 75%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-284 Improper Access Control1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
68This week | CVE-2019-9194Weaponized | elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.std42 · elfinder · CWE-78 | Critical9.8 | — | 96.7% | Feb 26, 2019 |
60This week | CVE-2021-32682Weaponized | Multiple vulnerabilities leading to RCEstd42 · elfinder · CWE-22 | Critical9.8 | — | 69.9% | Jun 14, 2021 |
52Plan | CVE-2021-43421Proof of concept | A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to std42 · elfinder · CWE-434 | Critical9.8 | — | 42.8% | Apr 7, 2022 |
51Plan | CVE-2022-26960Proof of concept | connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal.std42 · elfinder · CWE-22 | Critical9.1 | — | 51.0% | Mar 21, 2022 |
48Plan | CVE-2022-27115No exploit | In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.std42 · elfinder · CWE-434 | Critical9.8 | — | 28.6% | Apr 11, 2022 |
45Plan | CVE-2021-23394Proof of concept | Remote Code Execution (RCE)std42 · elfinder · CWE-434 | Critical9.8 | — | 18.9% | Jun 13, 2021 |
39Monitor | CVE-2023-52044No exploit | Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extensistd42 · elfinder · CWE-434 | Critical9.8 | — | 0.8% | Oct 31, 2024 |
39Monitor | CVE-2024-38909No exploit | Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control.std42 · elfinder · CWE-284 | Critical9.8 | — | 0.5% | Jul 30, 2024 |
37Monitor | CVE-2018-9109No exploit | Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a restd42 · elfinder · CWE-22 | Critical9.1 | — | 2.9% | Mar 28, 2018 |
37Monitor | CVE-2018-9110No exploit | Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a restd42 · elfinder · CWE-22 | Critical9.1 | — | 2.9% | Mar 28, 2018 |
36Monitor | CVE-2026-41247No exploit | elFinder: Command injection in resize background color parameter when using ImageMagick CLIstd42 · elfinder · CWE-78 | High8.9 | — | 2.7% | Apr 23, 2026 |
30Monitor | CVE-2019-6257No exploit | A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal std42 · elfinder · CWE-918 | High7.7 | — | 1.1% | Jan 14, 2019 |
27Monitor | CVE-2023-35840Proof of concept | _joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.std42 · elfinder · CWE-22 | Medium6.5 | — | 1.9% | Jun 18, 2023 |
24Monitor | CVE-2023-52045No exploit | Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.std42 · elfinder · CWE-79 | Medium6.1 | — | 0.3% | Oct 31, 2024 |
23Monitor | CVE-2019-5884No exploit | php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not sstd42 · elfinder · CWE-200 | Medium5.9 | — | 1.3% | Jan 10, 2019 |
21Monitor | CVE-2021-45919No exploit | Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.std42 · elfinder · CWE-79 | Medium5.4 | — | 0.6% | Feb 8, 2022 |
- CVE-2019-919468This week
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
CriticalCVSS 9.8WeaponizedEPSS 97%std42 · elfinderFeb 26, 2019
- CVE-2021-3268260This week
Multiple vulnerabilities leading to RCE
CriticalCVSS 9.8WeaponizedEPSS 70%std42 · elfinderJun 14, 2021
- CVE-2021-4342152Plan
A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to
CriticalCVSS 9.8Proof of conceptEPSS 43%std42 · elfinderApr 7, 2022
- CVE-2022-2696051Plan
connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal.
CriticalCVSS 9.1Proof of conceptEPSS 51%std42 · elfinderMar 21, 2022
- CVE-2022-2711548Plan
In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.
CriticalCVSS 9.8No exploitEPSS 29%std42 · elfinderApr 11, 2022
- CVE-2021-2339445Plan
Remote Code Execution (RCE)
CriticalCVSS 9.8Proof of conceptEPSS 19%std42 · elfinderJun 13, 2021
- CVE-2023-5204439Monitor
Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extensi
CriticalCVSS 9.8No exploitEPSS 1%std42 · elfinderOct 31, 2024
- CVE-2024-3890939Monitor
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control.
CriticalCVSS 9.8No exploitEPSS 0%std42 · elfinderJul 30, 2024
- CVE-2018-910937Monitor
Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a re
CriticalCVSS 9.1No exploitEPSS 3%std42 · elfinderMar 28, 2018
- CVE-2018-911037Monitor
Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a re
CriticalCVSS 9.1No exploitEPSS 3%std42 · elfinderMar 28, 2018
- CVE-2026-4124736Monitor
elFinder: Command injection in resize background color parameter when using ImageMagick CLI
HighCVSS 8.9No exploitEPSS 3%std42 · elfinderApr 23, 2026
- CVE-2019-625730Monitor
A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal
HighCVSS 7.7No exploitEPSS 1%std42 · elfinderJan 14, 2019
- CVE-2023-3584027Monitor
_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.
MediumCVSS 6.5Proof of conceptEPSS 2%std42 · elfinderJun 18, 2023
- CVE-2023-5204524Monitor
Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.
MediumCVSS 6.1No exploitEPSS 0%std42 · elfinderOct 31, 2024
- CVE-2019-588423Monitor
php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not s
MediumCVSS 5.9No exploitEPSS 1%std42 · elfinderJan 10, 2019
- CVE-2021-4591921Monitor
Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.
MediumCVSS 5.4No exploitEPSS 1%std42 · elfinderFeb 8, 2022