Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Std42

First CVE: Mar 28, 2018Active for: 8 yearsTotal CVEs: 16
62.5
VTI Score
TOP TARGET

Std42 maintains elFinder, a widely used open-source file manager component that is embedded across numerous web applications and content management platforms, making it a high-value target despite its narrow product scope. Vulnerabilities affecting this vendor skew strongly toward critical severity and frequently acquire public exploit code; the recurring weakness classes—path traversal, unrestricted file uploads, OS command injection, cross-site scripting, and server-side request forgery—reflect the inherent risks of a file-handling utility exposed to untrusted input and user interaction. Defenders should prioritize patching elFinder instances in internet-facing applications, as the combination of serious flaws and public tooling creates material exploitation risk; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
8.6
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Std42 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 28, 2018
8 years ago
Most Recent CVE
Apr 23, 2026
92 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-9194CRITICAL
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
Feb 26, 20199.892NOYES
CVE-2021-32682CRITICAL
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker
Jun 14, 20219.884NOYES
CVE-2021-43421CRITICAL
A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP c
Apr 7, 20229.867NOYES
CVE-2022-26960CRITICAL
connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the conf
Mar 21, 20229.161NOYES
CVE-2021-23394CRITICAL
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .
Jun 13, 20219.851NOYES
CVE-2022-27115CRITICAL
In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.
Apr 11, 20229.838NONO
CVE-2026-41247CRITICAL
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command.
Apr 23, 20269.830NONO
CVE-2023-52044CRITICAL
Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.
Oct 31, 20249.830NONO
CVE-2018-9109CRITICAL
Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessib
Mar 28, 20189.130NONO
CVE-2024-38909CRITICAL
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose
Jul 30, 20249.829NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
25%
69%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High1 (6.3%)
Unknown0 (0.0%)
User Interaction
None14 (87.5%)
Unknown0 (0.0%)
Required2 (12.5%)
Privileges Required
Low3 (18.8%)
High0 (0.0%)
None13 (81.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
12.5% of CVEs· 98th percentile
Nuclei
5 CVEs
31.2% of CVEs· 98th percentile
ExploitDB
1 CVE
6.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Std42.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Std42 — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Std42's Products

View all 3 CNAs →

Top CWEs