Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

element-hq — Vulnerabilities & Security Advisories 27

Browse all 27 CVE security advisories affecting element-hq. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Element-HQ develops and maintains Element, an open-source communication platform built on the Matrix protocol, facilitating secure messaging and collaboration for enterprises and individuals. The software’s architecture, which relies heavily on web technologies and server-side components, has historically exposed it to common web application vulnerabilities. Recorded Common Vulnerabilities and Exposures (CVEs) frequently involve cross-site scripting (XSS), allowing attackers to inject malicious scripts into web pages viewed by other users. Additionally, several incidents have highlighted issues related to improper access control and potential remote code execution (RCE) vectors within the underlying Synapse server implementation. These flaws often stem from complex integration points between the client interface and backend services. While the platform emphasizes end-to-end encryption for data privacy, the broader attack surface includes traditional web security risks. Recent patches have addressed critical privilege escalation bugs, underscoring the ongoing need for rigorous code auditing in this widely deployed communication infrastructure.

CVE ID Title CVSS Severity Published
CVE-2026-55850 Element Web: A malicious homeserver can inject HTML in Element Web using its homepage — element-web CWE-79 5.3 Medium 2026-08-21
CVE-2026-48007 Element Call reports full URLs of visited pages to analytics server — element-call CWE-200 8.6 High 2026-08-07
CVE-2026-45078 Synapse CPU starvation (Denial of Service) — synapse CWE-770 - - 2026-05-28
CVE-2026-45076 Synapse pagination denial of service — synapse CWE-20 - - 2026-05-28
CVE-2026-24044 ESS Community Helm Chart has a weak server key generation method — ess-helm CWE-336 9.1AI Critical AI 2026-02-12
CVE-2025-62425 Matrix Authentication Service account password can be changed using an authenticated session without supplying the current password — matrix-authentication-service CWE-620 8.3 High 2025-10-16
CVE-2025-61672 Synapse: Invalid device keys degrade federation functionality — synapse CWE-1287 6.5AI Medium AI 2025-10-08
CVE-2025-59161 In Element Web and Element Desktop, a malicious room can hide an unrelated room and cause it to be left when the malicious room is left — element-web CWE-20 7.5AI High AI 2025-09-16
CVE-2025-27599 Element X Android vulnerable to loading malicious web pages via received intent — element-x-android CWE-926 6.5 Medium 2025-04-18
CVE-2025-32026 Element Web could load a malicious instance of Element Call leaking media encryption keys — element-web CWE-497 3.8 Low 2025-04-08
CVE-2025-31126 Element X iOS allows the entity in control of the well-known file to break the confidentiality of embedded Element Call — element-x-ios CWE-200 5.3 Medium 2025-04-03
CVE-2025-31127 Element X Android allows the entity in control of the well-known file to break the confidentiality embedded Element Call — element-x-android CWE-200 5.3 Medium 2025-04-03
CVE-2025-30355 Synapse vulnerable to federation denial of service via malformed events — synapse CWE-20 7.1 High 2025-03-27
CVE-2025-27606 Element Android PIN autologout bypass — element-android CWE-488 5.1 Medium 2025-03-14
CVE-2024-37303 Synapse unauthenticated writes to the media repository allow planting of problematic content — synapse CWE-306 5.3 Medium 2024-12-03
CVE-2024-37302 Synapse denial of service through media disk space consumption — synapse CWE-770 7.5 High 2024-12-03
CVE-2024-52805 Synapse allows unsupported content types to lead to memory exhaustion — synapse CWE-770 7.5 - 2024-12-03
CVE-2024-52815 Synapse allows a a malformed invite to break the invitee's `/sync` — synapse CWE-20 - - 2024-12-03
CVE-2024-53867 Synapse Matrix has a partial room state leak via Sliding Sync — synapse CWE-497 4.3 Medium 2024-12-03
CVE-2024-53863 Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders — synapse CWE-434 6.5 - 2024-12-03
CVE-2024-51750 Element allows a malicious homeserver can modify events leading to unrenderable events or rooms — element-web CWE-248 5.0 Medium 2024-11-12
CVE-2024-51749 Element's thumbnails can be abused to misrepresent the content of an attachment — element-web CWE-451 3.5 Low 2024-11-12
CVE-2024-47779 Element Web vulnerable to potential exposure of access token via authenticated media — element-web CWE-200 7.5 - 2024-10-15
CVE-2024-47771 Element Desktop vulnerable to potential exposure of access token via authenticated media — element-desktop CWE-200 7.5 - 2024-10-15
CVE-2024-31208 Synapse's V2 state resolution weakness allows DoS from remote room members — synapse CWE-770 6.5 Medium 2024-04-23
CVE-2024-26132 Element Android can be asked to share internal files. — element-android CWE-200 4.0 Medium 2024-02-20
CVE-2024-26131 Element Android Intent Redirection — element-android CWE-923 8.4 High 2024-02-20

This page lists every published CVE security advisory associated with element-hq. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.