Elabftw is an open-source electronic laboratory notebook application used in research and academic environments, where its vulnerability profile clusters in a single product line addressing scientific data management and collaboration. Vulnerabilities affecting this vendor recur through web-layer input-handling and authentication weaknesses, including cross-site scripting, improper authentication mechanisms, and privilege-assignment flaws that are characteristic of collaborative web applications handling sensitive research data. A meaningful share of disclosures reach serious severity, and the application's role in research workflows makes authentication and access-control integrity particularly material to defenders. Live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elabftw over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12185HIGH eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may result in remote command execution. An attacker can use a us | May 20, 2019 | 8.8 | 49 | NO | YES |
CVE-2022-31007HIGH eLabFTW is an electronic lab notebook manager for research teams. Prior to version 4.3.0, a vulnerability allows an authenticated user with an administrator role in a team to assig | May 31, 2022 | 7.2 | 37 | NO | NO |
CVE-2021-43834CRITICAL eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows an attacker to authenticate as an existing user, | Dec 16, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-43833HIGH eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows any authenticated user to gain access to arbitrar | Dec 16, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-41171HIGH eLabFTW is an open source electronic lab notebook manager for research teams. In versions of eLabFTW before 4.1.0, it allows attackers to bypass a brute-force protection mechanism | Oct 22, 2021 | 8.8 | 27 | NO | NO |
CVE-2026-28510MEDIUM eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably preserve the multi-factor authentication state across authenti | May 5, 2026 | 5.9 | 25 | NO | NO |
CVE-2025-25206HIGH eLabFTW is an open source electronic lab notebook for research labs. Prior to version 5.1.15, an incorrect input validation could allow an authenticated user to read sensitive info | Feb 14, 2025 | 8.8 | 25 | NO | NO |
CVE-2026-28511MEDIUM eLabFTW is an open source electronic lab notebook. Prior to version 5.4.2, in certain cases, an authenticated user performing a numeric reference/search can return results that inc | Jun 1, 2026 | 4.3 | 22 | NO | NO |
CVE-2024-52586HIGH eLabFTW is an open source electronic lab notebook for research labs. A vulnerability has been found starting in version 4.6.0 and prior to version 5.1.0 that allows an attacker to | Dec 9, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-25632HIGH eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and conte | Oct 1, 2024 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elabftw.
Media articles that mention a CVE ID that affects a product developed by Elabftw — matched by CVE ID, not by vendor name.