CVE-2024-11145: Valorapps Easy Folder Listing Pro

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privileges of the Joomla! application. Fixed in versions 3.8 and 4.5.

Affected products

  • Valorapps Easy Folder Listing Pro: from 4.4, before 4.5 (fixed in 4.5); version 3.7 only

Published 2024-11-26. Last modified 2026-06-17.