Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Elabftw MEDIUM 5.9
CVE-2026-28510

eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably preserve the multi-factor authe…

Fix: 5.4.2+
Fix from $1,600 2026-05-05
Elabftw HIGH 8.8
CVE-2025-25206

eLabFTW is an open source electronic lab notebook for research labs. Prior to version 5.1.15, an incorrect input validation could allow an authentica…

Fix: 5.1.15+
Fix from $1,950 2025-02-14
Elabftw HIGH 7.8
CVE-2024-52586

eLabFTW is an open source electronic lab notebook for research labs. A vulnerability has been found starting in version 4.6.0 and prior to version 5.…

Fix: 5.1.9+
Fix from $1,950 2024-12-09
Elabftw MEDIUM 6.1
CVE-2024-47826

eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows an attacker to inject arbitrar…

Fix: 5.1.5+
Fix from $1,600 2024-10-14
Elabftw MEDIUM 6.5
CVE-2024-45408

eLabFTW is an open source electronic lab notebook for research labs. An incorrect permission check has been found that could allow an authenticated u…

Fix: 5.1.0+
Fix from $1,600 2024-10-01
Elabftw HIGH 8.8
CVE-2024-25632

eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a user account with certain privi…

Fix: 5.1.0+
Fix from $1,950 2024-10-01
Elabftw MEDIUM 5.4
CVE-2024-28100

eLabFTW is an open source electronic lab notebook for research labs. By uploading specially crafted files, a regular user can create a circumstance w…

Fix: 5.0.0+
Fix from $1,600 2024-09-02
Elabftw MEDIUM 5.4
CVE-2024-25633

eLabFTW is an open source electronic lab notebook for research labs. In an eLabFTW system, one can configure who is allowed to create new user accoun…

Fix: 5.0.0+
Fix from $1,600 2024-08-15
Elabftw HIGH 7.2
CVE-2022-31007EPSS 27%

eLabFTW is an electronic lab notebook manager for research teams. Prior to version 4.3.0, a vulnerability allows an authenticated user with an admini…

Fix: 4.3.0+
Fix from $1,950 2022-05-31
Elabftw CRITICAL 9.8
CVE-2021-43834

eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows an attacker to aut…

Fix: 4.2.0+
Fix from $2,300 2021-12-16
Elabftw HIGH 8.8
CVE-2021-43833

eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows any authenticated …

Fix: 4.2.0+
Fix from $1,950 2021-12-16
Elabftw HIGH 8.8
CVE-2021-41171

eLabFTW is an open source electronic lab notebook manager for research teams. In versions of eLabFTW before 4.1.0, it allows attackers to bypass a br…

Fix: 4.1.0+
Fix from $1,950 2021-10-22
Elabftw HIGH 8.8
CVE-2019-12185EPSS 18%

eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may result in remote command exec…

No fix yet
Fix from $1,950 2019-05-20
Elabftw MEDIUM 5.4
CVE-2017-1000478

ELabftw version 1.7.8 is vulnerable to stored cross-site scripting in the experiment infos component resulting in arbitrary execution of JavaScript a…

No fix yet
Fix from $1,600 2018-01-03