All 6 CVE vulnerabilities found in element-web, with AI-generated Chinese analysis, references, and POCs.
Vendor: element-hq
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-55850 | Element Web: A malicious homeserver can inject HTML in Element Web using its homepage CWE-79 | 5.3 | Medium | 2026-08-21 |
| CVE-2025-59161 | In Element Web and Element Desktop, a malicious room can hide an unrelated room and cause it to be left when the malicious room is left CWE-20 | 7.5AI | High AI | 2025-09-16 |
| CVE-2025-32026 | Element Web could load a malicious instance of Element Call leaking media encryption keys CWE-497 | 3.8 | Low | 2025-04-08 |
| CVE-2024-51750 | Element allows a malicious homeserver can modify events leading to unrenderable events or rooms CWE-248 | 5.0 | Medium | 2024-11-12 |
| CVE-2024-51749 | Element's thumbnails can be abused to misrepresent the content of an attachment CWE-451 | 3.5 | Low | 2024-11-12 |
| CVE-2024-47779 | Element Web vulnerable to potential exposure of access token via authenticated media CWE-200 | 7.5 | - | 2024-10-15 |
All 6 known CVE vulnerabilities affecting element-web with full Chinese analysis, references, and POCs where available.