Elkagroup develops web-based content management and gallery applications, with the observed vulnerability signal centered on application-layer input handling across its Image Gallery and ElkaPAX CMS products. The recurring weakness classes—SQL injection, improper input validation, and cross-site scripting—reflect typical web application security concerns in form and query processing. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elkagroup over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1446MEDIUM Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executab | Apr 27, 2009 | 6.5 | 29 | NO | YES |
CVE-2009-4569HIGH SQL injection vulnerability in elkagroup Image Gallery allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI under news/. | Jan 5, 2010 | 7.5 | 28 | NO | YES |
CVE-2008-5037HIGH SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter. | Nov 12, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-3461HIGH SQL injection vulnerability in property.php in elkagroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter. | Jun 27, 2007 | 7.5 | 28 | NO | YES |
CVE-2009-2930MEDIUM Cross-site scripting (XSS) vulnerability in the Search feature in elka CMS (aka Elkapax) allows remote attackers to inject arbitrary web script or HTML via the q parameter to the d | Aug 21, 2009 | 4.3 | 22 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elkagroup.
Media articles that mention a CVE ID that affects a product developed by Elkagroup — matched by CVE ID, not by vendor name.