Elgg records
11 published records for vendor elgg.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 45.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2011-2936No exploit | Elgg through 1.7.10 has a SQL injection vulnerabilityelgg · elgg · CWE-89 | Critical9.8 | — | 1.5% | Nov 12, 2019 |
30Monitor | CVE-2021-3980No exploit | Exposure of Private Personal Information to an Unauthorized Actor in elgg/elggelgg · elgg · CWE-359 | High7.5 | — | 1.6% | Dec 3, 2021 |
27Monitor | CVE-2012-6562No exploit | engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows remote attackers to creelgg · elgg · CWE-264 | Medium6.8 | — | 1.3% | May 23, 2013 |
24Monitor | CVE-2019-11016No exploit | Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect.elgg · elgg · CWE-601 | Medium6.1 | — | 1.2% | Apr 8, 2019 |
24Monitor | CVE-2011-2935No exploit | Elgg through 1.7.10 has XSSelgg · elgg · CWE-79 | Medium6.1 | — | 1.1% | Nov 12, 2019 |
23Monitor | CVE-2021-3964No exploit | Authorization Bypass Through User-Controlled Key in elgg/elggelgg · elgg · CWE-639 | Medium5.9 | — | 0.8% | Dec 1, 2021 |
21Monitor | CVE-2021-4072No exploit | Cross-site Scripting (XSS) - Stored in elgg/elggelgg · elgg · CWE-79 | Medium5.4 | — | 0.7% | Dec 24, 2021 |
20Monitor | CVE-2011-3733No exploit | Elgg 1.7.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path elgg · elgg · CWE-200 | Medium5.0 | — | 1.3% | Sep 23, 2011 |
17Monitor | CVE-2013-0234No exploit | Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg before 1.7.17 and 1.8.x before 1.8.13 allows remote attackers to injeelgg · elgg · CWE-79 | Medium4.3 | — | 1.5% | Feb 2, 2014 |
17Monitor | CVE-2012-6563No exploit | engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to elgg · elgg · CWE-264 | Medium4.3 | — | 1.2% | May 23, 2013 |
17Monitor | CVE-2012-6561No exploit | Cross-site scripting (XSS) vulnerability in engine/lib/views.php in Elgg before 1.8.5 allows remote attackers to inject arbitrary web scriptelgg · elgg · CWE-79 | Medium4.3 | — | 1.2% | May 23, 2013 |
- CVE-2011-293639Monitor
Elgg through 1.7.10 has a SQL injection vulnerability
CriticalCVSS 9.8No exploitEPSS 2%elgg · elggNov 12, 2019
- CVE-2021-398030Monitor
Exposure of Private Personal Information to an Unauthorized Actor in elgg/elgg
HighCVSS 7.5No exploitEPSS 2%elgg · elggDec 3, 2021
- CVE-2012-656227Monitor
engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows remote attackers to cre
MediumCVSS 6.8No exploitEPSS 1%elgg · elggMay 23, 2013
- CVE-2019-1101624Monitor
Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect.
MediumCVSS 6.1No exploitEPSS 1%elgg · elggApr 8, 2019
- CVE-2011-293524Monitor
Elgg through 1.7.10 has XSS
MediumCVSS 6.1No exploitEPSS 1%elgg · elggNov 12, 2019
- CVE-2021-396423Monitor
Authorization Bypass Through User-Controlled Key in elgg/elgg
MediumCVSS 5.9No exploitEPSS 1%elgg · elggDec 1, 2021
- CVE-2021-407221Monitor
Cross-site Scripting (XSS) - Stored in elgg/elgg
MediumCVSS 5.4No exploitEPSS 1%elgg · elggDec 24, 2021
- CVE-2011-373320Monitor
Elgg 1.7.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path
MediumCVSS 5.0No exploitEPSS 1%elgg · elggSep 23, 2011
- CVE-2013-023417Monitor
Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg before 1.7.17 and 1.8.x before 1.8.13 allows remote attackers to inje
MediumCVSS 4.3No exploitEPSS 1%elgg · elggFeb 2, 2014
- CVE-2012-656317Monitor
engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to
MediumCVSS 4.3No exploitEPSS 1%elgg · elggMay 23, 2013
- CVE-2012-656117Monitor
Cross-site scripting (XSS) vulnerability in engine/lib/views.php in Elgg before 1.8.5 allows remote attackers to inject arbitrary web script
MediumCVSS 4.3No exploitEPSS 1%elgg · elggMay 23, 2013