CVEs we hold for Element-hq
Records whose assigning authority named Element-hq as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-55850Element Web: A malicious homeserver can inject HTML in Element Web using its homepageelement-hq element-web
CVE-2026-48007Element Call reports full URLs of visited pages to analytics serverelement-hq element-call
CVE-2026-24044ESS Community Helm Chart has a weak server key generation methodelement-hq matrix-tools
CVE-2025-62425Matrix Authentication Service account password can be changed using an authenticated session without supplying the…element-hq matrix-authentication-service
CVE-2025-59161In Element Web and Element Desktop, a malicious room can hide an unrelated room and cause it to be left when the…element-hq element-web
CVE-2025-32026Element Web could load a malicious instance of Element Call leaking media encryption keyselement-hq element-web
CVE-2025-31127Element X Android allows the entity in control of the well-known file to break the confidentiality embedded Element Callelement-hq element-x-android
CVE-2025-31126Element X iOS allows the entity in control of the well-known file to break the confidentiality of embedded Element Callelement-hq element-x-ios
CVE-2025-30355Synapse vulnerable to federation denial of service via malformed eventselement-hq synapse
CVE-2025-27599Element X Android vulnerable to loading malicious web pages via received intentelement-hq element-x-android
CVE-2024-53863Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoderselement-hq synapse
CVE-2024-52805Synapse allows unsupported content types to lead to memory exhaustionelement-hq synapse
CVE-2024-51750Element allows a malicious homeserver can modify events leading to unrenderable events or roomselement-hq element-web
CVE-2024-51749Element's thumbnails can be abused to misrepresent the content of an attachmentelement-hq element-web
CVE-2024-47779Element Web vulnerable to potential exposure of access token via authenticated mediaelement-hq element-web
CVE-2024-47771Element Desktop vulnerable to potential exposure of access token via authenticated mediaelement-hq element-desktop
CVE-2024-37303Synapse unauthenticated writes to the media repository allow planting of problematic contentelement-hq synapse
CVE-2024-31208Synapse's V2 state resolution weakness allows DoS from remote room memberselement-hq synapse
27 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.