Known Vulnerabilities for products from Elgg
Listed below are 11 of the newest known vulnerabilities associated with the vendor "Elgg".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65650 json | Not Provided | 2026-07-22 | 2026-07-22 | |
| CVE-2021-4072 json | elgg is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 5.4 - MEDIUM | 2021-12-24 | 2022-01-03 |
| CVE-2021-3980 json | elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor | 7.5 - HIGH | 2021-12-03 | 2021-12-06 |
| CVE-2021-3964 json | elgg is vulnerable to Authorization Bypass Through User-Controlled Key | 5.9 - MEDIUM | 2021-12-01 | 2021-12-02 |
| CVE-2019-11016 json | Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect. | 6.1 - MEDIUM | 2019-04-08 | 2019-04-09 |
| CVE-2013-0234 json | Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg before 1.7.17 and 1.8.x before 1.8.13 allows remote at... | Not Provided | 2014-02-02 | 2026-04-29 |
| CVE-2012-6563 json | engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remot... | Not Provided | 2013-05-23 | 2026-04-29 |
| CVE-2012-6562 json | engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows remote a... | Not Provided | 2013-05-23 | 2026-04-29 |
| CVE-2012-6561 json | Cross-site scripting (XSS) vulnerability in engine/lib/views.php in Elgg before 1.8.5 allows remote attackers to inject arbit... | Not Provided | 2013-05-23 | 2026-04-29 |
| CVE-2011-3733 json | Elgg 1.7.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the ins... | Not Provided | 2011-09-23 | 2026-04-29 |
| CVE-2011-2936 json | Elgg through 1.7.10 has a SQL injection vulnerability | 9.8 - CRITICAL | 2019-11-12 | 2019-11-12 |
| CVE-2011-2935 json | Elgg through 1.7.10 has XSS | 6.1 - MEDIUM | 2019-11-12 | 2019-11-13 |
Known software with vulnerabilities from Elgg
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Elgg | Elgg | 1.0 |