element-hq
Communicationsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting element-hq.
- CVE-2026-55850Element Web: A malicious homeserver can inject HTML in Element Web using its homepage
- CVE-2026-48007Element Call reports full URLs of visited pages to analytics server
- CVE-2026-45078Synapse CPU starvation (Denial of Service)5.5
- CVE-2026-45076Synapse pagination denial of service2.7
- CVE-2026-24044ESS Community Helm Chart has a weak server key generation method
- CVE-2025-62425Matrix Authentication Service account password can be changed using an authenticated session without supplying the current password8.3
- CVE-2025-61672Synapse: Invalid device keys degrade federation functionality
- CVE-2025-59161In Element Web and Element Desktop, a malicious room can hide an unrelated room and cause it to be left when the malicious room is left
- CVE-2025-27599Element X Android vulnerable to loading malicious web pages via received intent6.5
- CVE-2025-32026Element Web could load a malicious instance of Element Call leaking media encryption keys3.8
- CVE-2025-31126Element X iOS allows the entity in control of the well-known file to break the confidentiality of embedded Element Call5.3
- CVE-2025-31127Element X Android allows the entity in control of the well-known file to break the confidentiality embedded Element Call5.3
- CVE-2025-30355Synapse vulnerable to federation denial of service via malformed events7.1
- CVE-2025-27606Element Android PIN autologout bypass5.1
- CVE-2024-37303Synapse unauthenticated writes to the media repository allow planting of problematic content5.3