Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Vulnerability List
Found 14 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2025-62793 eLabFTW HTML / CSS Injection via Malicious SVG Upload Leads to Credential Theft / Clickjacking elabftwelabftw Medium 6.8 2025-10-27 21:25:46 Deep Dive
CVE-2025-25206 Incorrect input validation could allow an authenticated user to read sensitive information elabftwelabftw High 8.3 2025-02-14 16:47:05 Deep Dive
CVE-2024-52586 eLabFTW MFA bypass elabftwelabftw Medium 5.4 2024-12-09 18:38:43 Deep Dive
CVE-2024-47826 eLabFTW vulnerable to HTML Injection in extended search error message elabftwelabftw Low 3.5 2024-10-14 17:59:26 Deep Dive
CVE-2024-45408 eLabFTW contains a direct and indirect information disclosure elabftwelabftw High 7.5 2024-10-01 14:53:48 Deep Dive
CVE-2024-25632 Unauthorised granting of administrator privileges over arbitrary teams under certain circumstances elabftwelabftw High 8.6 2024-10-01 14:36:50 Deep Dive
CVE-2024-28100 Stored Cross-site Scripting leading to arbitrary actions taken on behalf of users in elabftw elabftwelabftw High 8.9 2024-09-02 16:10:12 Deep Dive
CVE-2024-25633 In eLabFTW, if administrators can create users, users can too elabftwelabftw Medium 5.4 2024-08-15 18:23:58 Deep Dive
CVE-2022-31178 Improper Authorization in eLabFTW elabftwelabftw Medium 4.3 2022-08-01 19:10:11 Deep Dive
CVE-2022-31007 Privilege escalation from administrator in eLabFTW elabftwelabftw Medium 4.9 2022-05-31 19:30:13 Deep Dive
CVE-2021-43834 Incorrect Authentication in elabftw elabftwelabftw Critical 9.1 2021-12-15 23:20:15 Deep Dive
CVE-2021-43833 Account takeover in eLabFTW elabftwelabftw High 8.1 2021-12-15 23:20:10 Deep Dive
CVE-2021-41171 Bypass bruteforce protection on login form in elabftw elabftwelabftw Medium 5.9 2021-10-22 18:55:11 Deep Dive
CVE-2021-32698 Blind Server-Side Request Forgery (SSRF) in eLabFTW elabftwelabftw Medium 6.8 2021-06-21 21:15:11 Deep Dive