Element
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 19 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from February 1, 2022 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Element Web: A malicious homeserver can inject HTML in Element Web using its homepage
Synapse pagination denial of service
Synapse CPU starvation (Denial of Service)
Matrix Authentication Service account password can be changed using an authenticated session without supplying the current password
In Element Web and Element Desktop, a malicious room can hide an unrelated room and cause it to be left when the malicious room is left
Element X Android vulnerable to loading malicious web pages via received intent
Element Web could load a malicious instance of Element Call leaking media encryption keys
Element X iOS allows the entity in control of the well-known file to break the confidentiality of embedded Element Call
Element X Android allows the entity in control of the well-known file to break the confidentiality embedded Element Call
Monitor Element in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.