Elog Project maintains a specialized electronic logbook system used in research and scientific environments, with a focused product line centered on Elog and Elogd. The vulnerability exposure recurs through access-control and information-disclosure weakness classes—including cleartext transmission, sensitive-data exposure, missing authorization, and improper access control—that reflect the authentication and confidentiality demands of a collaborative logging platform. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elog Project over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3993HIGH ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can recover a user's password hash by sending a crafted HTTP | Dec 17, 2019 | 7.5 | 47 | NO | NO |
CVE-2019-3995HIGH ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference. A remote unauthenticated attacker can crash the ELOG server by send | Dec 17, 2019 | 7.5 | 38 | NO | NO |
CVE-2025-64349HIGH ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset, and take control of the targe | Oct 31, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-62618HIGH ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other users when they open the file. Because ELOG includes username | Oct 31, 2025 | 8.0 | 26 | NO | NO |
CVE-2019-3992HIGH ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the server's configuration file by sending an HTTP | Dec 17, 2019 | 7.5 | 25 | NO | NO |
CVE-2008-7004HIGH Buffer overflow in Electronic Logbook (ELOG) before 2.7.1 has unknown impact and attack vectors, possibly related to elog.c. | Aug 19, 2009 | 10.0 | 25 | NO | NO |
CVE-2025-64348HIGH ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifically enabled with the "-x" comma | Oct 31, 2025 | 7.1 | 24 | NO | NO |
CVE-2019-3994HIGH ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a use after free. A remote unauthenticated attacker can crash the ELOG server by sending multip | Dec 17, 2019 | 7.5 | 24 | NO | NO |
CVE-2016-6342HIGH elog 3.1.1 allows remote attackers to post data as any username in the logbook. | Jun 27, 2017 | 7.5 | 24 | NO | NO |
CVE-2019-3996MEDIUM ELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted HTTP POST requests. | Dec 17, 2019 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elog Project.
Media articles that mention a CVE ID that affects a product developed by Elog Project — matched by CVE ID, not by vendor name.