Vendor
high
advisory
SSRF Protection Bypass in elFinder via DNS Rebinding
1 rule 4 TTPs 1 CVEelFinder 2.1.69 and earlier are vulnerable to a DNS rebinding SSRF attack when PHP cURL is unavailable, allowing attackers to access internal or loopback network services.
elFinder +1
web-application
rce
file-upload
cve-2026-81891
1r
4t
1c
updated
high
advisory
elFinder MySQL Volume Driver SQL Injection (CVE-2026-44521)
2 rules 1 TTPAn authenticated SQL injection vulnerability (CVE-2026-44521) exists in the elFinder MySQL volume driver (`elFinderVolumeMySQL`) allowing any logged-in user, including read-only users, to inject SQL through a crafted `target` file hash leading to unauthorized data disclosure and denial of service.
elfinder
sql-injection
web-application
2r
1t