It has been discovered that the extension ftpbrowser is doing incorrect authentication in some files, making it open for exploiting.
Multiple vulnerabilities have been found in the third party extension "mysqldumper". Full read/write access to the connected database and other related issues.