CVE-2013-5951: Extplorer
Low severity, CVSS 2.6. EPSS: 1.9% chance of exploitation in the next 30 days.
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) application.js.php in scripts/ or (2) admin.php, (3) copy_move.php, (4) functions.php, (5) header.php, or (6) upload.php in include/.
Affected products
- Extplorer Extplorer: version 2.1.3 only
Published 2014-03-25. Last modified 2026-06-16.