Extplorer is a file-management application with a focused but notably exposed product footprint, appearing across both standalone and component deployments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code; the durable signal concentrates in web-layer weaknesses including cross-site scripting, path traversal, cross-site request forgery, and improper access controls that are characteristic of file-browser interfaces exposed to untrusted users. Defenders should treat Extplorer instances as high-value targets for exploitation, particularly in multi-user or web-accessible deployments; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Extplorer over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6710CRITICAL ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login request to index.php. | Oct 7, 2018 | 9.8 | 56 | NO | YES |
CVE-2016-4313HIGH Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitrary files via a .. (dot dot) in an archive file. | Apr 24, 2017 | 7.8 | 41 | NO | YES |
CVE-2008-4764MEDIUM Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the | Oct 28, 2008 | 5.0 | 37 | NO | YES |
CVE-2023-54335CRITICAL eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this fla | Jan 13, 2026 | 9.8 | 33 | NO | NO |
CVE-2019-25097CRITICAL A vulnerability was found in soerennb eXtplorer up to 2.1.12 and classified as critical. Affected by this issue is some unknown functionality of the component Directory Content Han | Jan 5, 2023 | 9.8 | 31 | NO | NO |
CVE-2019-25098CRITICAL A vulnerability was found in soerennb eXtplorer up to 2.1.12. It has been classified as critical. This affects an unknown part of the file include/archive.php of the component Arch | Jan 5, 2023 | 9.8 | 30 | NO | NO |
CVE-2019-7305CRITICAL Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP. Introduced in the Makefile patch file debian/patc | Apr 10, 2020 | 9.8 | 30 | NO | NO |
CVE-2023-27842HIGH Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code via the index.php compenent | Mar 21, 2023 | 8.8 | 28 | NO | NO |
CVE-2023-29657HIGH eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing php pages with arbitrary code executions. | May 12, 2023 | 8.8 | 27 | NO | NO |
CVE-2017-12756HIGH Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter. | Aug 9, 2017 | 7.2 | 22 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Extplorer.
Media articles that mention a CVE ID that affects a product developed by Extplorer — matched by CVE ID, not by vendor name.