Studio-42/elFinder vulnerabilities
CVEs whose affected-version data names the Studio-42/elFinder package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-81890Medium· 5.4elFinder is an open-source file manager for web, written in JavaScript using jQuery UI
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in php/elFinderConnector.class.php, so validateCsrfToken(…
CVE-2026-81891High· 8.1elFinder is an open-source file manager for web, written in JavaScript using jQuery UI
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeType…
CVE-2026-81889High· 8.6elFinder is an open-source file manager for web, written in JavaScript using jQuery UI
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable becau…