Elfinder
Vendor:
First CVE: Mar 28, 2018 · Active for 8 years
16
Total CVEs
More Total CVEs than 92% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
8.6
Avg CVSS
Higher Avg CVSS than 76% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Elfinder over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 28, 2018
8 years ago
Most Recent CVE
Apr 23, 2026
92 days ago
CVE Severity & Scoring
Elfinder16 CVEs
25%
69%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High1 (6.3%)
Unknown0 (0.0%)
User Interaction
None14 (87.5%)
Unknown0 (0.0%)
Required2 (12.5%)
Privileges Required
Low3 (18.8%)
High0 (0.0%)
None13 (81.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9194CRITICAL elFinder before 2.1.48 has a command injection vulnerability in the PHP connector. | Feb 26, 2019 | 9.8 | 92 | NO | YES |
CVE-2021-32682CRITICAL elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker | Jun 14, 2021 | 9.8 | 84 | NO | YES |
CVE-2021-43421CRITICAL A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP c | Apr 7, 2022 | 9.8 | 67 | NO | YES |
CVE-2022-26960CRITICAL connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the conf | Mar 21, 2022 | 9.1 | 61 | NO | YES |
CVE-2021-23394CRITICAL The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses . | Jun 13, 2021 | 9.8 | 51 | NO | YES |
CVE-2022-27115CRITICAL In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload. | Apr 11, 2022 | 9.8 | 38 | NO | NO |
CVE-2026-41247CRITICAL elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command. | Apr 23, 2026 | 9.8 | 30 | NO | NO |
CVE-2023-52044CRITICAL Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension. | Oct 31, 2024 | 9.8 | 30 | NO | NO |
CVE-2018-9109CRITICAL Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessib | Mar 28, 2018 | 9.1 | 30 | NO | NO |
CVE-2024-38909CRITICAL Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose | Jul 30, 2024 | 9.8 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
12.5% of CVEs· 97th percentile
Nuclei
5 CVEs
31.2% of CVEs· 98th percentile
ExploitDB
1 CVE
6.2% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Elfinder
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.1.64 | 1 | 9.8 | 0.5% | 0 | 0 |
| 2.1.62 | 2 | 8.0 | 0.5% | 0 | 0 |
| 2.1.60 | 1 | 9.8 | 28.6% | 0 | 0 |