Elfinder

Vendor:

First CVE: Mar 28, 2018 · Active for 8 years

16
Total CVEs
More Total CVEs than 92% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
8.6
Avg CVSS
Higher Avg CVSS than 76% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Elfinder over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 28, 2018
8 years ago
Most Recent CVE
Apr 23, 2026
92 days ago

CVE Severity & Scoring

Elfinder16 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High1 (6.3%)
Unknown0 (0.0%)
User Interaction
None14 (87.5%)
Unknown0 (0.0%)
Required2 (12.5%)
Privileges Required
Low3 (18.8%)
High0 (0.0%)
None13 (81.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
Feb 26, 20199.892NOYES
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker
Jun 14, 20219.884NOYES
A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP c
Apr 7, 20229.867NOYES
connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the conf
Mar 21, 20229.161NOYES
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .
Jun 13, 20219.851NOYES
In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.
Apr 11, 20229.838NONO
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command.
Apr 23, 20269.830NONO
Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.
Oct 31, 20249.830NONO
Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessib
Mar 28, 20189.130NONO
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose
Jul 30, 20249.829NONO

Exploit Exposure

Signals from CVEs in this product scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
12.5% of CVEs· 97th percentile
Nuclei
5 CVEs
31.2% of CVEs· 98th percentile
ExploitDB
1 CVE
6.2% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (16 CVEs).

Media Mentions

Signals from CVEs in this product scope (16 CVEs).

Top CNAs Publishing CVEs For Elfinder

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.1.6419.80.5%00
2.1.6228.00.5%00
2.1.6019.828.6%00