| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-62793 | eLabFTW HTML / CSS Injection via Malicious SVG Upload Leads to Credential Theft / Clickjacking | elabftw | elabftw | Medium | 6.8 | 2025-10-27 21:25:46 | Deep Dive |
| CVE-2025-25206 | Incorrect input validation could allow an authenticated user to read sensitive information | elabftw | elabftw | High | 8.3 | 2025-02-14 16:47:05 | Deep Dive |
| CVE-2024-52586 | eLabFTW MFA bypass | elabftw | elabftw | Medium | 5.4 | 2024-12-09 18:38:43 | Deep Dive |
| CVE-2024-47826 | eLabFTW vulnerable to HTML Injection in extended search error message | elabftw | elabftw | Low | 3.5 | 2024-10-14 17:59:26 | Deep Dive |
| CVE-2024-45408 | eLabFTW contains a direct and indirect information disclosure | elabftw | elabftw | High | 7.5 | 2024-10-01 14:53:48 | Deep Dive |
| CVE-2024-25632 | Unauthorised granting of administrator privileges over arbitrary teams under certain circumstances | elabftw | elabftw | High | 8.6 | 2024-10-01 14:36:50 | Deep Dive |
| CVE-2024-28100 | Stored Cross-site Scripting leading to arbitrary actions taken on behalf of users in elabftw | elabftw | elabftw | High | 8.9 | 2024-09-02 16:10:12 | Deep Dive |
| CVE-2024-25633 | In eLabFTW, if administrators can create users, users can too | elabftw | elabftw | Medium | 5.4 | 2024-08-15 18:23:58 | Deep Dive |
| CVE-2022-31178 | Improper Authorization in eLabFTW | elabftw | elabftw | Medium | 4.3 | 2022-08-01 19:10:11 | Deep Dive |
| CVE-2022-31007 | Privilege escalation from administrator in eLabFTW | elabftw | elabftw | Medium | 4.9 | 2022-05-31 19:30:13 | Deep Dive |
| CVE-2021-43834 | Incorrect Authentication in elabftw | elabftw | elabftw | Critical | 9.1 | 2021-12-15 23:20:15 | Deep Dive |
| CVE-2021-43833 | Account takeover in eLabFTW | elabftw | elabftw | High | 8.1 | 2021-12-15 23:20:10 | Deep Dive |
| CVE-2021-41171 | Bypass bruteforce protection on login form in elabftw | elabftw | elabftw | Medium | 5.9 | 2021-10-22 18:55:11 | Deep Dive |
| CVE-2021-32698 | Blind Server-Side Request Forgery (SSRF) in eLabFTW | elabftw | elabftw | Medium | 6.8 | 2021-06-21 21:15:11 | Deep Dive |