Skip to content
Noroxi

Elgg records

11 published records for vendor elgg.

All records

11 records
  • CVE-2011-2936
    39Monitor

    Elgg through 1.7.10 has a SQL injection vulnerability

    CriticalCVSS 9.8No exploitEPSS 2%

    elgg · elggNov 12, 2019

  • CVE-2021-3980
    30Monitor

    Exposure of Private Personal Information to an Unauthorized Actor in elgg/elgg

    HighCVSS 7.5No exploitEPSS 2%

    elgg · elggDec 3, 2021

  • CVE-2012-6562
    27Monitor

    engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows remote attackers to cre

    MediumCVSS 6.8No exploitEPSS 1%

    elgg · elggMay 23, 2013

  • Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect.

    MediumCVSS 6.1No exploitEPSS 1%

    elgg · elggApr 8, 2019

  • CVE-2011-2935
    24Monitor

    Elgg through 1.7.10 has XSS

    MediumCVSS 6.1No exploitEPSS 1%

    elgg · elggNov 12, 2019

  • CVE-2021-3964
    23Monitor

    Authorization Bypass Through User-Controlled Key in elgg/elgg

    MediumCVSS 5.9No exploitEPSS 1%

    elgg · elggDec 1, 2021

  • CVE-2021-4072
    21Monitor

    Cross-site Scripting (XSS) - Stored in elgg/elgg

    MediumCVSS 5.4No exploitEPSS 1%

    elgg · elggDec 24, 2021

  • CVE-2011-3733
    20Monitor

    Elgg 1.7.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path

    MediumCVSS 5.0No exploitEPSS 1%

    elgg · elggSep 23, 2011

  • CVE-2013-0234
    17Monitor

    Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg before 1.7.17 and 1.8.x before 1.8.13 allows remote attackers to inje

    MediumCVSS 4.3No exploitEPSS 1%

    elgg · elggFeb 2, 2014

  • CVE-2012-6563
    17Monitor

    engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to

    MediumCVSS 4.3No exploitEPSS 1%

    elgg · elggMay 23, 2013

  • CVE-2012-6561
    17Monitor

    Cross-site scripting (XSS) vulnerability in engine/lib/views.php in Elgg before 1.8.5 allows remote attackers to inject arbitrary web script

    MediumCVSS 4.3No exploitEPSS 1%

    elgg · elggMay 23, 2013