Std42 maintains elFinder, a widely used open-source file manager component that is embedded across numerous web applications and content management platforms, making it a high-value target despite its narrow product scope. Vulnerabilities affecting this vendor skew strongly toward critical severity and frequently acquire public exploit code; the recurring weakness classes—path traversal, unrestricted file uploads, OS command injection, cross-site scripting, and server-side request forgery—reflect the inherent risks of a file-handling utility exposed to untrusted input and user interaction. Defenders should prioritize patching elFinder instances in internet-facing applications, as the combination of serious flaws and public tooling creates material exploitation risk; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Std42 over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9194CRITICAL elFinder before 2.1.48 has a command injection vulnerability in the PHP connector. | Feb 26, 2019 | 9.8 | 92 | NO | YES |
CVE-2021-32682CRITICAL elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker | Jun 14, 2021 | 9.8 | 84 | NO | YES |
CVE-2021-43421CRITICAL A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP c | Apr 7, 2022 | 9.8 | 67 | NO | YES |
CVE-2022-26960CRITICAL connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the conf | Mar 21, 2022 | 9.1 | 61 | NO | YES |
CVE-2021-23394CRITICAL The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses . | Jun 13, 2021 | 9.8 | 51 | NO | YES |
CVE-2022-27115CRITICAL In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload. | Apr 11, 2022 | 9.8 | 38 | NO | NO |
CVE-2026-41247CRITICAL elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command. | Apr 23, 2026 | 9.8 | 30 | NO | NO |
CVE-2023-52044CRITICAL Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension. | Oct 31, 2024 | 9.8 | 30 | NO | NO |
CVE-2018-9109CRITICAL Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessib | Mar 28, 2018 | 9.1 | 30 | NO | NO |
CVE-2024-38909CRITICAL Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose | Jul 30, 2024 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Std42.
Media articles that mention a CVE ID that affects a product developed by Std42 — matched by CVE ID, not by vendor name.