studio-42 has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was August 2026 with 3. The median CVSS is 8.1 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Worst active — by depth score
CVE-2026-81889High· 8.6elFinder is an open-source file manager for web, written in JavaScript using jQuery UI47CVE-2026-81891High· 8.1elFinder is an open-source file manager for web, written in JavaScript using jQuery UI45CVE-2026-81890Medium· 5.4elFinder is an open-source file manager for web, written in JavaScript using jQuery UI30
studio-42 vulnerabilities
CVEs affecting studio-42, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-81890Medium· 5.4elFinder is an open-source file manager for web, written in JavaScript using jQuery UI
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in php/elFinderConnector.class.php, so validateCsrfToken(…
CVE-2026-81891High· 8.1elFinder is an open-source file manager for web, written in JavaScript using jQuery UI
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeType…
CVE-2026-81889High· 8.6elFinder is an open-source file manager for web, written in JavaScript using jQuery UI
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable becau…