Show filters
154 Total Results
Displaying 1-10 of 154
Sort by:
Attacker Value
Moderate

CVE-2021-32682

Disclosure Date: June 14, 2021 (last updated February 22, 2025)
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues were patched in version 2.1.59. As a workaround, ensure the connector is not exposed without authentication.
Attacker Value
Very High

CVE-2021-42224

Disclosure Date: October 13, 2021 (last updated February 23, 2025)
SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.
Attacker Value
Unknown

CVE-2021-43421

Disclosure Date: April 07, 2022 (last updated February 23, 2025)
A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code.
Attacker Value
Moderate

elFinder Command Injection v<2.1.48

Disclosure Date: February 26, 2019 (last updated October 06, 2023)
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
0
Attacker Value
Unknown

CVE-2024-13440

Disclosure Date: February 09, 2025 (last updated February 14, 2025)
The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in all versions up to, and including, 7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into an already existing query to store cross-site scripting in store reviews.
Attacker Value
Unknown

CVE-2025-23645

Disclosure Date: February 04, 2025 (last updated February 05, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Optimize Worldwide Find Content IDs allows Reflected XSS. This issue affects Find Content IDs: from n/a through 1.0.
0
Attacker Value
Unknown

CVE-2025-24734

Disclosure Date: January 27, 2025 (last updated January 28, 2025)
Missing Authorization vulnerability in CodeSolz Better Find and Replace allows Privilege Escalation. This issue affects Better Find and Replace: from n/a through 1.6.7.
0
Attacker Value
Unknown

CVE-2025-23727

Disclosure Date: January 23, 2025 (last updated January 24, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound AZ Content Finder allows Reflected XSS. This issue affects AZ Content Finder: from n/a through 0.1.
0
Attacker Value
Unknown

CVE-2025-23557

Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Kathleen Malone Find Your Reps allows Stored XSS.This issue affects Find Your Reps: from n/a through 1.2.
0
Attacker Value
Unknown

CVE-2023-46082

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Missing Authorization vulnerability in Cyberlord92 Broken Link Checker | Finder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Broken Link Checker | Finder: from n/a through 2.4.2.
0