Home/Product/elabftw
Product

elabftw

16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-28510
< 5.4.2
eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably preserve the
5.9MEDIUM
CVE-2025-25206
< 5.1.15
eLabFTW is an open source electronic lab notebook for research labs. Prior to version 5.1.15, an incorrect input validation could
8.3HIGH
CVE-2024-52586
>= 4.6.0 and < 5.1.9
eLabFTW is an open source electronic lab notebook for research labs. A vulnerability has been found starting in version 4.6.0 and
5.4MEDIUM
CVE-2024-47826
< 5.1.5
eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows an attacker
3.5LOW
CVE-2024-45408
>= 4.4.0 and < 5.1.0
eLabFTW is an open source electronic lab notebook for research labs. An incorrect permission check has been found that could allow
7.5HIGH
CVE-2024-25632
>= 4.6.0 and < 5.1.0
eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a user account
8.6HIGH
CVE-2024-28100
< 5.0.0
eLabFTW is an open source electronic lab notebook for research labs. By uploading specially crafted files, a regular user can crea
8.9HIGH
CVE-2024-25633
>= 4.4.0 and < 5.0.0
eLabFTW is an open source electronic lab notebook for research labs. In an eLabFTW system, one can configure who is allowed to cre
5.4MEDIUM
CVE-2022-31178
< 4.3.4
eLabFTW is an electronic lab notebook manager for research teams. A vulnerability was discovered which allows a logged in user to
4.3MEDIUM
CVE-2022-31007
< 4.3.0
eLabFTW is an electronic lab notebook manager for research teams. Prior to version 4.3.0, a vulnerability allows an authenticated
4.9MEDIUM
CVE-2021-43834
< 4.2.0
eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows
9.1CRITICAL
CVE-2021-43833
< 4.2.0
eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows
8.1HIGH
CVE-2021-41171
< 4.1.0
eLabFTW is an open source electronic lab notebook manager for research teams. In versions of eLabFTW before 4.1.0, it allows attac
5.9MEDIUM
CVE-2021-32698
< 4.0.0
eLabFTW is an open source electronic lab notebook for research labs. This vulnerability allows an attacker to make GET requests on
6.8MEDIUM
CVE-2019-12185
all versions
eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may result in
8.8HIGH
CVE-2017-1000478
all versions
ELabftw version 1.7.8 is vulnerable to stored cross-site scripting in the experiment infos component resulting in arbitrary execut
5.4MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin