Element-Web
Element-HQ · 6 CVEs
CVE-2026-55850
MEDIUM
Element Web: A malicious homeserver can inject HTML in Element Web using its homepage
Aug 21, 2026
CVE-2025-59161
LOW
In Element Web and Element Desktop, a malicious room can hide an unrelated room and cause it to be left when the malici…
Sep 16, 2025
CVE-2025-32026
LOW
Element Web could load a malicious instance of Element Call leaking media encryption keys
Apr 8, 2025
CVE-2024-51750
MEDIUM
Element allows a malicious homeserver can modify events leading to unrenderable events or rooms
Nov 12, 2024
CVE-2024-51749
LOW
Element's thumbnails can be abused to misrepresent the content of an attachment
Nov 12, 2024
CVE-2024-47779
HIGH
Element Web vulnerable to potential exposure of access token via authenticated media
Oct 15, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-55850 | Element Web: A malicious homeserver can inject HTML in Element Web using its homepage | MEDIUM | 0.55% | Aug 21, 2026 |
| CVE-2025-59161 | In Element Web and Element Desktop, a malicious room can hide an unrelated room and cause it to be left when the malicious room is left | LOW | 0.41% | Sep 16, 2025 |
| CVE-2025-32026 | Element Web could load a malicious instance of Element Call leaking media encryption keys | LOW | 0.16% | Apr 8, 2025 |
| CVE-2024-51750 | Element allows a malicious homeserver can modify events leading to unrenderable events or rooms | MEDIUM | 0.50% | Nov 12, 2024 |
| CVE-2024-51749 | Element's thumbnails can be abused to misrepresent the content of an attachment | LOW | 0.34% | Nov 12, 2024 |
| CVE-2024-47779 | Element Web vulnerable to potential exposure of access token via authenticated media | HIGH | 0.43% | Oct 15, 2024 |
Showing 1 to 6 of 6 CVEs