Elgg is an open-source social networking and community platform whose vulnerability profile concentrates in a single, widely embedded product serving educational institutions, nonprofits, and hosted community deployments. The recurring vulnerability classes reflect the platform's web-facing architecture and data-handling role: cross-site scripting, SQL injection, authorization bypass, and information-disclosure flaws cluster around input validation, access control, and sensitive-data management. Defenders should inventory Elgg installations, prioritize patches addressing authentication and injection issues, and treat this platform as a deployment-specific risk rather than a broad ecosystem threat; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elgg over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-2936CRITICAL Elgg through 1.7.10 has a SQL injection vulnerability | Nov 12, 2019 | 9.8 | 30 | NO | NO |
CVE-2021-3980HIGH elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor | Dec 3, 2021 | 7.5 | 25 | NO | NO |
CVE-2026-65650MEDIUM Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload. | Jul 22, 2026 | 4.3 | 24 | NO | NO |
CVE-2019-11016MEDIUM Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect. | Apr 8, 2019 | 6.1 | 22 | NO | NO |
CVE-2021-4072MEDIUM elgg is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Dec 24, 2021 | 5.4 | 21 | NO | NO |
CVE-2021-3964MEDIUM elgg is vulnerable to Authorization Bypass Through User-Controlled Key | Dec 1, 2021 | 5.9 | 21 | NO | NO |
CVE-2011-2935MEDIUM Elgg through 1.7.10 has XSS | Nov 12, 2019 | 6.1 | 21 | NO | NO |
CVE-2012-6562MEDIUM engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows remote attackers to create arbitrary accounts. | May 23, 2013 | 6.8 | 20 | NO | NO |
CVE-2011-3733MEDIUM Elgg 1.7.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by | Sep 23, 2011 | 5.0 | 18 | NO | NO |
CVE-2013-0234MEDIUM Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg before 1.7.17 and 1.8.x before 1.8.13 allows remote attackers to inject arbitrary web script or HTML via the | Feb 2, 2014 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elgg.
Media articles that mention a CVE ID that affects a product developed by Elgg — matched by CVE ID, not by vendor name.