Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

elabftw — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in elabftw, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the elabftw laboratory notebook software, specifically categorized under general web application weaknesses. It compiles known issues affecting the product’s integrity, confidentiality, and availability across its various releases. The content covers vulnerability records identified from early 2020 through the present, providing a comprehensive timeline of security flaws discovered and patched in the ecosystem. This range includes critical remote code execution flaws, authentication bypasses, and cross-site scripting issues that have impacted user data safety. Visitors can utilize this resource to track vendor advisories from the elabftw development team, gaining insight into their response times and remediation strategies. Users can also understand broader weakness classes by observing how specific architectural flaws manifest in this particular software context. Furthermore, researchers and administrators can look up the product’s vulnerability history to assess risk levels for their own deployments or to compare against other similar laboratory management systems. This structured overview supports informed decision-making for system upgrades, patch management, and security audits without requiring deep technical digging into individual patch notes for every single issue. By centralizing these data points, the page offers a clearer picture of the software’s security posture over time.

Vendor: elabftw

CVE ID Title CVSS Severity Published
CVE-2026-28511 elabftw has entry title leakage through autocompletion search CWE-200 4.3 Medium 2026-06-01
CVE-2026-28510 elabftw allows MFA bypass during login CWE-302 5.9 Medium 2026-05-05
CVE-2025-62793 eLabFTW HTML / CSS Injection via Malicious SVG Upload Leads to Credential Theft / Clickjacking CWE-79 6.8 Medium 2025-10-27
CVE-2025-25206 Incorrect input validation could allow an authenticated user to read sensitive information CWE-89 8.3 High 2025-02-14
CVE-2024-52586 eLabFTW MFA bypass CWE-288 5.4 Medium 2024-12-09
CVE-2024-47826 eLabFTW vulnerable to HTML Injection in extended search error message CWE-79 3.5 Low 2024-10-14
CVE-2024-45408 eLabFTW contains a direct and indirect information disclosure CWE-284 7.5 High 2024-10-01
CVE-2024-25632 Unauthorised granting of administrator privileges over arbitrary teams under certain circumstances CWE-266 8.6 High 2024-10-01
CVE-2024-28100 Stored Cross-site Scripting leading to arbitrary actions taken on behalf of users in elabftw CWE-79 8.9 High 2024-09-02
CVE-2024-25633 In eLabFTW, if administrators can create users, users can too CWE-266 5.4 Medium 2024-08-15
CVE-2022-31178 Improper Authorization in eLabFTW CWE-863 4.3 Medium 2022-08-01
CVE-2022-31007 Privilege escalation from administrator in eLabFTW CWE-842 4.9 Medium 2022-05-31
CVE-2021-43834 Incorrect Authentication in elabftw CWE-287 9.1 Critical 2021-12-15
CVE-2021-43833 Account takeover in eLabFTW CWE-287 8.1 High 2021-12-15
CVE-2021-41171 Bypass bruteforce protection on login form in elabftw CWE-307 5.9 Medium 2021-10-22
CVE-2021-32698 Blind Server-Side Request Forgery (SSRF) in eLabFTW CWE-918 6.8 Medium 2021-06-21

All 16 known CVE vulnerabilities affecting elabftw with full Chinese analysis, references, and POCs where available.