{"schema_version":1,"title":"studio-42/elfinder (Packagist) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 19 vulnerabilities in studio-42/elfinder (Packagist): 0 in the last 7 days and 3 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-81891, was published on 31 August 2026.","url":"https://junglewise.ai/threats/technologies/studio-42-elfinder","json_url":"https://junglewise.ai/threats/technologies/studio-42-elfinder.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/studio-42-elfinder","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":19,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":3,"last_90_days":3,"last_365_days":5},"latest":[{"cve":"CVE-2026-81891","cvss":8.1,"epss":0.009,"slug":"cve-2026-81891-elfinder-zip-extraction-mime-filter-bypass-allowing-php-upload","title":"elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinder","severity":"high","exploited":false,"published_at":"2026-08-31T21:17:52.757+00:00","url":"https://junglewise.ai/threats/cve-2026-81891-elfinder-zip-extraction-mime-filter-bypass-allowing-php-upload"},{"cve":"CVE-2026-81890","cvss":5.4,"epss":0.0018,"slug":"cve-2026-81890-elfinder-csrf-in-netmount-allows-forced-ftp-mounts","title":"elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted fro","severity":"medium","exploited":false,"published_at":"2026-08-31T21:17:52.603+00:00","url":"https://junglewise.ai/threats/cve-2026-81890-elfinder-csrf-in-netmount-allows-forced-ftp-mounts"},{"cve":"CVE-2026-81889","cvss":8.6,"epss":0.0055,"slug":"cve-2026-81889-elfinder-ssrf-protection-bypass-via-dns-rebinding","title":"elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinde","severity":"high","exploited":false,"published_at":"2026-08-31T21:17:52.46+00:00","url":"https://junglewise.ai/threats/cve-2026-81889-elfinder-ssrf-protection-bypass-via-dns-rebinding"},{"cve":"CVE-2026-44521","cvss":8.8,"epss":0.0044,"slug":"cve-2026-44521-studio-42-elfinder-sql-injection-in-elfindervolumemysql","title":"Studio-42 elFinder SQL injection in elFinderVolumeMySQL","severity":"high","exploited":false,"published_at":"2026-05-27T18:16:23.953+00:00","url":"https://junglewise.ai/threats/cve-2026-44521-studio-42-elfinder-sql-injection-in-elfindervolumemysql"},{"cve":"CVE-2026-41247","cvss":3.1,"epss":0.0265,"slug":"cve-2026-41247-elfinder-command-injection-in-resize-background-color-parameter","title":"elFinder: Command injection in resize background color parameter when using ImageMagick CLI","severity":"low","exploited":false,"published_at":"2026-04-17T22:33:51+00:00","url":"https://junglewise.ai/threats/cve-2026-41247-elfinder-command-injection-in-resize-background-color-parameter"},{"cve":"CVE-2024-38909","cvss":3.1,"epss":0.0048,"slug":"cve-2024-38909-studio-42-elfinder-vulnerable-to-incorrect-access-control","title":"Studio 42 elFinder vulnerable to Incorrect Access Control","severity":"low","exploited":false,"published_at":"2024-07-30T15:31:28+00:00","url":"https://junglewise.ai/threats/cve-2024-38909-studio-42-elfinder-vulnerable-to-incorrect-access-control"},{"slug":"duplicate-advisory-elfinder-vulnerable-to-path-traversal-in-dab9bee1","title":"Duplicate Advisory: elFinder vulnerable to path traversal in LocalVolumeDriver connector","severity":"info","exploited":false,"published_at":"2023-06-19T03:30:19+00:00","url":"https://junglewise.ai/threats/duplicate-advisory-elfinder-vulnerable-to-path-traversal-in-dab9bee1"},{"cve":"CVE-2023-35840","cvss":3.1,"epss":0.0194,"slug":"cve-2023-35840-elfinder-vulnerable-to-path-traversal-in-localvolumedriver","title":"elFinder vulnerable to path traversal in LocalVolumeDriver connector","severity":"low","exploited":false,"published_at":"2023-06-14T16:37:01+00:00","url":"https://junglewise.ai/threats/cve-2023-35840-elfinder-vulnerable-to-path-traversal-in-localvolumedriver"},{"cve":"CVE-2019-9194","cvss":3,"epss":0.9673,"slug":"cve-2019-9194-elfinder-command-injection-vulnerability-in-the-php-connector","title":"elFinder command injection vulnerability in the PHP connector","severity":"low","exploited":false,"published_at":"2022-05-13T01:23:02+00:00","url":"https://junglewise.ai/threats/cve-2019-9194-elfinder-command-injection-vulnerability-in-the-php-connector"},{"cve":"CVE-2018-9110","cvss":3.1,"epss":0.0288,"slug":"cve-2018-9110-directory-traversal-in-studio-42-elfinder","title":"Directory Traversal in Studio 42 elFinder","severity":"low","exploited":false,"published_at":"2022-05-13T01:06:17+00:00","url":"https://junglewise.ai/threats/cve-2018-9110-directory-traversal-in-studio-42-elfinder"},{"cve":"CVE-2019-6257","cvss":3.1,"epss":0.011,"slug":"cve-2019-6257-elfinder-server-side-request-forgery-ssrf","title":"elFinder Server Side Request Forgery (SSRF)","severity":"low","exploited":false,"published_at":"2022-05-13T01:06:16+00:00","url":"https://junglewise.ai/threats/cve-2019-6257-elfinder-server-side-request-forgery-ssrf"},{"cve":"CVE-2019-5884","cvss":3.1,"epss":0.0128,"slug":"cve-2019-5884-sensitive-data-exposure-in-elfinder","title":"Sensitive Data Exposure in elFinder","severity":"low","exploited":false,"published_at":"2022-05-13T01:06:16+00:00","url":"https://junglewise.ai/threats/cve-2019-5884-sensitive-data-exposure-in-elfinder"},{"cve":"CVE-2018-9109","cvss":3.1,"epss":0.0294,"slug":"cve-2018-9109-elfinder-path-traversal-vulnerability","title":"elFinder Path Traversal vulnerability","severity":"low","exploited":false,"published_at":"2022-05-13T01:06:16+00:00","url":"https://junglewise.ai/threats/cve-2018-9109-elfinder-path-traversal-vulnerability"},{"cve":"CVE-2022-27115","cvss":3.1,"epss":0.2859,"slug":"cve-2022-27115-rce-in-studio-42-elfinder-on-windows-before-2-1-61","title":"RCE in Studio-42 elFinder on Windows before 2.1.61","severity":"low","exploited":false,"published_at":"2022-04-12T00:00:34+00:00","url":"https://junglewise.ai/threats/cve-2022-27115-rce-in-studio-42-elfinder-on-windows-before-2-1-61"},{"cve":"CVE-2021-43421","cvss":3.1,"epss":0.4278,"slug":"cve-2021-43421-elfinder-unrestricted-file-upload-vulnerability","title":"elFinder Unrestricted File Upload vulnerability","severity":"low","exploited":false,"published_at":"2022-04-08T00:00:23+00:00","url":"https://junglewise.ai/threats/cve-2021-43421-elfinder-unrestricted-file-upload-vulnerability"},{"cve":"CVE-2022-26960","cvss":3.1,"epss":0.5099,"slug":"cve-2022-26960-path-traversal-in-studio-42-elfinder-through-2-1-60","title":"Path Traversal in Studio-42 elFinder through 2.1.60","severity":"low","exploited":false,"published_at":"2022-03-22T00:00:41+00:00","url":"https://junglewise.ai/threats/cve-2022-26960-path-traversal-in-studio-42-elfinder-through-2-1-60"},{"cve":"CVE-2021-45919","cvss":3.1,"epss":0.0063,"slug":"cve-2021-45919-studio-42-elfinder-allows-stored-xss","title":"Studio 42 elFinder allows stored XSS","severity":"low","exploited":false,"published_at":"2022-02-10T00:00:32+00:00","url":"https://junglewise.ai/threats/cve-2021-45919-studio-42-elfinder-allows-stored-xss"},{"cve":"CVE-2021-32682","cvss":3.1,"epss":0.6993,"slug":"cve-2021-32682-elfinder-before-2-1-59-contains-multiple-vulnerabilities-leading","title":"elFinder before 2.1.59 contains multiple vulnerabilities leading to RCE","severity":"low","exploited":false,"published_at":"2021-06-16T17:04:29+00:00","url":"https://junglewise.ai/threats/cve-2021-32682-elfinder-before-2-1-59-contains-multiple-vulnerabilities-leading"},{"cve":"CVE-2021-23394","cvss":3.1,"epss":0.1894,"slug":"cve-2021-23394-elfinder-unsafe-upload-filtering-leading-to-remote-code-execution","title":"elFinder unsafe upload filtering leading to remote code execution","severity":"low","exploited":false,"published_at":"2021-06-15T15:51:02+00:00","url":"https://junglewise.ai/threats/cve-2021-23394-elfinder-unsafe-upload-filtering-leading-to-remote-code-execution"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"wwbn/avideo (Packagist)","slug":"wwbn-avideo","vulnerabilities":169,"url":"https://junglewise.ai/threats/technologies/wwbn-avideo"},{"name":"getgrav/grav (Packagist)","slug":"getgrav-grav","vulnerabilities":144,"url":"https://junglewise.ai/threats/technologies/getgrav-grav"},{"name":"thorsten/phpmyfaq (Packagist)","slug":"thorsten-phpmyfaq","vulnerabilities":138,"url":"https://junglewise.ai/threats/technologies/thorsten-phpmyfaq"},{"name":"pimcore/pimcore (Packagist)","slug":"pimcore-pimcore","vulnerabilities":136,"url":"https://junglewise.ai/threats/technologies/pimcore-pimcore"},{"name":"dolibarr/dolibarr (Packagist)","slug":"dolibarr-dolibarr","vulnerabilities":125,"url":"https://junglewise.ai/threats/technologies/dolibarr-dolibarr"},{"name":"drupal/core (Packagist)","slug":"packagist-drupal-core","vulnerabilities":116,"url":"https://junglewise.ai/threats/technologies/packagist-drupal-core"},{"name":"librenms/librenms (Packagist)","slug":"librenms-librenms","vulnerabilities":113,"url":"https://junglewise.ai/threats/technologies/librenms-librenms"},{"name":"microweber/microweber (Packagist)","slug":"microweber-microweber","vulnerabilities":106,"url":"https://junglewise.ai/threats/technologies/microweber-microweber"},{"name":"concrete5/concrete5 (Packagist)","slug":"concrete5-concrete5","vulnerabilities":93,"url":"https://junglewise.ai/threats/technologies/concrete5-concrete5"},{"name":"craftcms/cms (Packagist)","slug":"craftcms-cms","vulnerabilities":90,"url":"https://junglewise.ai/threats/technologies/craftcms-cms"},{"name":"snipe/snipe-it (Packagist)","slug":"snipe-snipe-it","vulnerabilities":80,"url":"https://junglewise.ai/threats/technologies/snipe-snipe-it"},{"name":"phpmyfaq/phpmyfaq (Packagist)","slug":"phpmyfaq-phpmyfaq","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/phpmyfaq-phpmyfaq"}],"technology":{"hub":true,"name":"studio-42/elfinder (Packagist)","slug":"studio-42-elfinder","vendor":{"name":"Packagist","slug":"packagist","url":"https://junglewise.ai/threats/vendors/packagist"},"aliases":[],"homepage":"https://studio-42.github.io/elFinder/","repo_url":"https://github.com/Studio-42/elFinder","description":"A web-based file manager for software using the elFinder framework.","url":"https://junglewise.ai/threats/technologies/studio-42-elfinder"},"most_severe":[{"cve":"CVE-2026-44521","cvss":8.8,"epss":0.0044,"slug":"cve-2026-44521-studio-42-elfinder-sql-injection-in-elfindervolumemysql","title":"Studio-42 elFinder SQL injection in elFinderVolumeMySQL","severity":"high","exploited":false,"published_at":"2026-05-27T18:16:23.953+00:00","url":"https://junglewise.ai/threats/cve-2026-44521-studio-42-elfinder-sql-injection-in-elfindervolumemysql"},{"cve":"CVE-2026-81889","cvss":8.6,"epss":0.0055,"slug":"cve-2026-81889-elfinder-ssrf-protection-bypass-via-dns-rebinding","title":"elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinde","severity":"high","exploited":false,"published_at":"2026-08-31T21:17:52.46+00:00","url":"https://junglewise.ai/threats/cve-2026-81889-elfinder-ssrf-protection-bypass-via-dns-rebinding"},{"cve":"CVE-2026-81891","cvss":8.1,"epss":0.009,"slug":"cve-2026-81891-elfinder-zip-extraction-mime-filter-bypass-allowing-php-upload","title":"elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinder","severity":"high","exploited":false,"published_at":"2026-08-31T21:17:52.757+00:00","url":"https://junglewise.ai/threats/cve-2026-81891-elfinder-zip-extraction-mime-filter-bypass-allowing-php-upload"},{"cve":"CVE-2026-81890","cvss":5.4,"epss":0.0018,"slug":"cve-2026-81890-elfinder-csrf-in-netmount-allows-forced-ftp-mounts","title":"elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted fro","severity":"medium","exploited":false,"published_at":"2026-08-31T21:17:52.603+00:00","url":"https://junglewise.ai/threats/cve-2026-81890-elfinder-csrf-in-netmount-allows-forced-ftp-mounts"},{"cve":"CVE-2021-32682","cvss":3.1,"epss":0.6993,"slug":"cve-2021-32682-elfinder-before-2-1-59-contains-multiple-vulnerabilities-leading","title":"elFinder before 2.1.59 contains multiple vulnerabilities leading to RCE","severity":"low","exploited":false,"published_at":"2021-06-16T17:04:29+00:00","url":"https://junglewise.ai/threats/cve-2021-32682-elfinder-before-2-1-59-contains-multiple-vulnerabilities-leading"},{"cve":"CVE-2022-26960","cvss":3.1,"epss":0.5099,"slug":"cve-2022-26960-path-traversal-in-studio-42-elfinder-through-2-1-60","title":"Path Traversal in Studio-42 elFinder through 2.1.60","severity":"low","exploited":false,"published_at":"2022-03-22T00:00:41+00:00","url":"https://junglewise.ai/threats/cve-2022-26960-path-traversal-in-studio-42-elfinder-through-2-1-60"},{"cve":"CVE-2021-43421","cvss":3.1,"epss":0.4278,"slug":"cve-2021-43421-elfinder-unrestricted-file-upload-vulnerability","title":"elFinder Unrestricted File Upload vulnerability","severity":"low","exploited":false,"published_at":"2022-04-08T00:00:23+00:00","url":"https://junglewise.ai/threats/cve-2021-43421-elfinder-unrestricted-file-upload-vulnerability"},{"cve":"CVE-2022-27115","cvss":3.1,"epss":0.2859,"slug":"cve-2022-27115-rce-in-studio-42-elfinder-on-windows-before-2-1-61","title":"RCE in Studio-42 elFinder on Windows before 2.1.61","severity":"low","exploited":false,"published_at":"2022-04-12T00:00:34+00:00","url":"https://junglewise.ai/threats/cve-2022-27115-rce-in-studio-42-elfinder-on-windows-before-2-1-61"},{"cve":"CVE-2021-23394","cvss":3.1,"epss":0.1894,"slug":"cve-2021-23394-elfinder-unsafe-upload-filtering-leading-to-remote-code-execution","title":"elFinder unsafe upload filtering leading to remote code execution","severity":"low","exploited":false,"published_at":"2021-06-15T15:51:02+00:00","url":"https://junglewise.ai/threats/cve-2021-23394-elfinder-unsafe-upload-filtering-leading-to-remote-code-execution"},{"cve":"CVE-2018-9109","cvss":3.1,"epss":0.0294,"slug":"cve-2018-9109-elfinder-path-traversal-vulnerability","title":"elFinder Path Traversal vulnerability","severity":"low","exploited":false,"published_at":"2022-05-13T01:06:16+00:00","url":"https://junglewise.ai/threats/cve-2018-9109-elfinder-path-traversal-vulnerability"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}