Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 306 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.90% | — | ElfinderAI | 31/8/2026 | 9/9/2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeTypeNormalize(). Because the .phtml, .phar, .php5, and .php3 extensions are absent… | |
| Aplazada | Media (5.4) | 0.18% | — | ElfinderAI | 31/8/2026 | 9/9/2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in php/elFinderConnector.class.php, so validateCsrfToken() is not called for this state-changing operation. In the shipped… | |
| Aplazada | Alta (8.6) | 0.55% | — | ElfinderAI | 31/8/2026 | 9/9/2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable because validate_address() validates $info['ip'], but get_remote_contents() selects… | |
| Aplazada | Alta (8.8) | 0.44% | — | ElfinderAI | 27/5/2026 | 17/6/2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolumeMySQL) allows any logged-in user, including users with read-only access to the affected volume, to inject SQL through… | |
| Analizada | Alta (8.9) | 2.7% | — | Std42 Elfinder | 23/4/2026 | 17/6/2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command. The bg (background color) parameter is accepted from user input and passed through image resize/rotate processing. In configurations that… | |
| Aplazada | Alta (8.7) | 0.39% | — | Chamilo LMSAIElfinderAI | 20/2/2026 | 17/6/2026 | Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute PHP files through the elfinder filemanager module. Attackers can upload files with image headers in the social myfiles section, rename them to PHP extensions, and execute arbitrary code by accessing… | |
| Aplazada | Media (6.5) | 0.76% | — | ElfinderAI | 13/8/2025 | 17/6/2026 | Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to delete arbitrary files. Successful exploitation of this vulnerability requires a site owner to explicitly make an instance of the file… | |
| Aplazada | Crítica (9.3) | 3.6% | — | BuilderengineAIElfinderAIJquery File UploadAI | 10/7/2025 | 17/6/2026 | An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file manager and its use of the jQuery File Upload plugin. The plugin fails to properly validate or restrict file types or locations during upload operations, allowing an attacker to upload a malicious .php… | |
| Analizada | Media (6.1) | 0.27% | — | Std42 Elfinder | 31/10/2024 | 17/6/2026 | Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability. | |
| Analizada | Crítica (9.8) | 0.79% | — | Std42 Elfinder | 31/10/2024 | 17/6/2026 | Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension. | |
| Modificada | Crítica (9.8) | 0.48% | — | Std42 Elfinder | 30/7/2024 | 9/7/2026 | Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc. | |
| Modificada | Media (6.5) | 1.9% | — | Std42 Elfinder | 19/6/2023 | 17/6/2026 | _joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector. | |
| Modificada | Crítica (9.8) | 29% | — | Std42 Elfinder | 11/4/2022 | 17/6/2026 | In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload. | |
| Modificada | Crítica (9.8) | 43% | — | Std42 Elfinder | 7/4/2022 | 17/6/2026 | A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code. | |
| Modificada | Crítica (9.1) | 51% | — | Std42 Elfinder | 21/3/2022 | 17/6/2026 | connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths. | |
| Modificada | Media (5.4) | 0.63% | — | Std42 Elfinder | 8/2/2022 | 17/6/2026 | Studio 42 elFinder through 2.1.31 allows XSS via an SVG document. | |
| Modificada | Crítica (9.8) | 1.7% | — | Elfinder.netcore Project Elfinder.netcore | 1/9/2021 | 17/6/2026 | This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file path. Due to missing sanitation of the user input and a missing check of the generated path its possible to escape the Files directory via path traversal | |
| Modificada | Crítica (9.8) | 1.4% | — | Elfinder.netcore Project Elfinder.netcore | 1/9/2021 | 17/6/2026 | This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to arbitrary extraction due to insufficient validation. | |
| Modificada | Alta (7.5) | 1.7% | — | Elfinder.aspnet Project Elfinder.aspnet | 28/7/2021 | 17/6/2026 | This affects the package elFinder.AspNet before 1.1.1. The user-controlled file name is not properly sanitized before it is used to create a file system path. | |
| Modificada | Alta (7.5) | 2.0% | — | Elfinder.net.core Project Elfinder.net.core | 14/7/2021 | 17/6/2026 | This affects the package elFinder.Net.Core from 0 and before 1.2.4. The user-controlled file name is not properly sanitized before it is used to create a file system path. | |
| Modificada | Crítica (9.8) | 70% | — | Std42 Elfinder | 14/6/2021 | 17/6/2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues were… | |
| Modificada | Crítica (9.8) | 19% | — | Std42 Elfinder | 13/6/2021 | 17/6/2026 | The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP. | |
| Modificada | Crítica (9.8) | 97% | — | Std42 Elfinder | 26/2/2019 | 17/6/2026 | elFinder before 2.1.48 has a command injection vulnerability in the PHP connector. | |
| Modificada | Alta (7.7) | 1.1% | — | Std42 Elfinder | 14/1/2019 | 17/6/2026 | A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network resources. This occurs in get_remote_contents() in php/elFinder.class.php. | |
| Modificada | Media (5.9) | 1.3% | — | Std42 Elfinder | 10/1/2019 | 17/6/2026 | php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set. |