Show filters
93 Total Results
Displaying 1-10 of 93
Sort by:
Attacker Value
Moderate

CVE-2021-32682

Disclosure Date: June 14, 2021 (last updated February 22, 2025)
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues were patched in version 2.1.59. As a workaround, ensure the connector is not exposed without authentication.
Attacker Value
Very High

CVE-2021-42224

Disclosure Date: October 13, 2021 (last updated February 23, 2025)
SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.
Attacker Value
Unknown

CVE-2021-43421

Disclosure Date: April 07, 2022 (last updated February 23, 2025)
A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code.
Attacker Value
Moderate

elFinder Command Injection v<2.1.48

Disclosure Date: February 26, 2019 (last updated October 06, 2023)
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
0
Attacker Value
Unknown

CVE-2024-13440

Disclosure Date: February 09, 2025 (last updated February 14, 2025)
The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in all versions up to, and including, 7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into an already existing query to store cross-site scripting in store reviews.
Attacker Value
Unknown

CVE-2025-23727

Disclosure Date: January 23, 2025 (last updated January 24, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound AZ Content Finder allows Reflected XSS. This issue affects AZ Content Finder: from n/a through 0.1.
0
Attacker Value
Unknown

CVE-2023-46082

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Missing Authorization vulnerability in Cyberlord92 Broken Link Checker | Finder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Broken Link Checker | Finder: from n/a through 2.4.2.
0
Attacker Value
Unknown

CVE-2024-12121

Disclosure Date: December 19, 2024 (last updated December 19, 2024)
The Broken Link Checker | Finder plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the 'moblc_check_link' function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Attacker Value
Unknown

CVE-2024-51697

Disclosure Date: November 09, 2024 (last updated November 10, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Doofinder allows Reflected XSS.This issue affects Doofinder: from n/a through 0.5.4.
0
Attacker Value
Unknown

CVE-2024-51181

Disclosure Date: October 29, 2024 (last updated November 05, 2024)
A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/admin/profile.php in PHPGurukul IFSC Code Finder Project v1.0, which allows remote attackers to execute arbitrary code via " searchifsccode" parameter.