ElggCVEs & Vulnerabilities

11 CVEs affecting Elgg products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

elgg 106
CVE-2021-4072MEDIUM

elgg is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

24 Dec 2021
5.4
CVSS
CVE-2021-3980HIGH

elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor

3 Dec 2021
7.5
CVSS
CVE-2021-3964MEDIUM

elgg is vulnerable to Authorization Bypass Through User-Controlled Key

1 Dec 2021
5.9
CVSS
CVE-2011-2936CRITICAL

Elgg through 1.7.10 has a SQL injection vulnerability

12 Nov 2019
9.8
CVSS
CVE-2011-2935MEDIUM

Elgg through 1.7.10 has XSS

12 Nov 2019
6.1
CVSS
CVE-2019-11016MEDIUM

Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect.

9 Apr 2019
6.1
CVSS
CVE-2013-0234MEDIUM

Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg before 1.7.17 and 1.8.x before 1.8.13 allows remote attackers to inject arbitrary web script or HTML via the params[twitter_username] parameter to action/widgets/save.

2 Feb 2014
4.3
CVSS
CVE-2012-6563MEDIUM

engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to read private entities via unspecified vectors.

23 May 2013
4.3
CVSS
CVE-2012-6562MEDIUM

engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows remote attackers to create arbitrary accounts.

23 May 2013
6.8
CVSS
CVE-2012-6561MEDIUM

Cross-site scripting (XSS) vulnerability in engine/lib/views.php in Elgg before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the view parameter to index.php. NOTE: some of these details are obtained from third party information.

23 May 2013
4.3
CVSS
CVE-2011-3733MEDIUM

Elgg 1.7.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by vendors/simpletest/test/visual_test.php and certain other files.

24 Sep 2011
5.0
CVSS
← PrevPage 1 / 1Next →