Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Extplorer

First CVE: Oct 28, 2008Active for: 18 yearsTotal CVEs: 18
44.3
VTI Score
High

Extplorer is a file-management application with a focused but notably exposed product footprint, appearing across both standalone and component deployments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code; the durable signal concentrates in web-layer weaknesses including cross-site scripting, path traversal, cross-site request forgery, and improper access controls that are characteristic of file-browser interfaces exposed to untrusted users. Defenders should treat Extplorer instances as high-value targets for exploitation, particularly in multi-user or web-accessible deployments; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Extplorer over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 28, 2008
17 years ago
Most Recent CVE
Jan 13, 2026
192 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-6710CRITICAL
ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login request to index.php.
Oct 7, 20189.856NOYES
CVE-2016-4313HIGH
Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitrary files via a .. (dot dot) in an archive file.
Apr 24, 20177.841NOYES
CVE-2008-4764MEDIUM
Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the
Oct 28, 20085.037NOYES
CVE-2023-54335CRITICAL
eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this fla
Jan 13, 20269.833NONO
CVE-2019-25097CRITICAL
A vulnerability was found in soerennb eXtplorer up to 2.1.12 and classified as critical. Affected by this issue is some unknown functionality of the component Directory Content Han
Jan 5, 20239.831NONO
CVE-2019-25098CRITICAL
A vulnerability was found in soerennb eXtplorer up to 2.1.12. It has been classified as critical. This affects an unknown part of the file include/archive.php of the component Arch
Jan 5, 20239.830NONO
CVE-2019-7305CRITICAL
Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP. Introduced in the Makefile patch file debian/patc
Apr 10, 20209.830NONO
CVE-2023-27842HIGH
Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code via the index.php compenent
Mar 21, 20238.828NONO
CVE-2023-29657HIGH
eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing php pages with arbitrary code executions.
May 12, 20238.827NONO
CVE-2017-12756HIGH
Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter.
Aug 9, 20177.222NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
11%
39%
22%
28%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (5.6%)
Network11 (61.1%)
Unknown6 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (66.7%)
High0 (0.0%)
Unknown6 (33.3%)
User Interaction
None8 (44.4%)
Unknown6 (33.3%)
Required4 (22.2%)
Privileges Required
Low3 (16.7%)
High1 (5.6%)
None8 (44.4%)
Unknown6 (33.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
5.6% of CVEs· 98th percentile
Nuclei
1 CVE
5.6% of CVEs· 96th percentile
ExploitDB
2 CVEs
11.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Extplorer.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Extplorer — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Extplorer's Products

View all 8 CNAs →

Top CWEs