Skip to main content

Vendor archive

extplorer CVEs

Beta · best-effort

18 CVEs tagged to vendor extplorer2 Critical, 4 High, 9 Medium, 3 Low, 0 Unrated.

CVE-2023-54335

Published Jan 13, 2026

eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this fl…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-13058

Published Nov 12, 2025

A security flaw has been discovered in soerennb eXtplorer up to 2.1.15. The affected element is an unknown function of the component Filename Handler. The manipulation results in…

CVSS 5.1 · Medium
evidence mentions
6
Buzz score
30.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2023-29657

Published May 12, 2023

eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing php pages with arbitrary code executions.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27842

Published Mar 21, 2023

Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code via the index.php compenent

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-25098

Published Jan 5, 2023

A vulnerability was found in soerennb eXtplorer up to 2.1.12. It has been classified as critical. This affects an unknown part of the file include/archive.php of the component Arc…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-25097

Published Jan 5, 2023

A vulnerability was found in soerennb eXtplorer up to 2.1.12 and classified as critical. Affected by this issue is some unknown functionality of the component Directory Content Ha…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-25096

Published Jan 5, 2023

A vulnerability has been found in soerennb eXtplorer up to 2.1.12 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-6710

Published Oct 7, 2018

ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login request to index.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12756

Published Aug 9, 2017

Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4313

Published Apr 24, 2017

Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitrary files via a .. (dot dot) in an archive file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5660

Published Oct 16, 2015

Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP cod…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0896

Published Mar 18, 2015

Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5951

Published Mar 25, 2014

Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inject arbitrary web script or HTML via the…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-3454

Published Aug 7, 2012

eXtplorer 2.1.0b6 uses world writable permissions for the /var/lib/extplorer/ftp_tmp directory, which allows local users to delete or overwrite arbitrary files.

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-3362

Published Jul 12, 2012

Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of administrators for requests that add an ad…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4764

Published Oct 28, 2008

Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1