DHTMLX records
5 published records for vendor dhtmlx.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 40%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2026-41553No exploit | Remote Code Execution in PDF Export Moduledhtmlx · pdf export module · CWE-78 | Critical10.0 | — | 1.0% | May 15, 2026 |
36Monitor | CVE-2026-41552No exploit | Path Traversal in PDF Export Moduledhtmlx · pdf export module · CWE-22 | Critical9.2 | — | 0.6% | May 15, 2026 |
26Monitor | CVE-2024-55213No exploit | Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the File Listindhtmlx · file explorer · CWE-22 | Medium6.5 | — | 0.8% | Feb 7, 2025 |
26Monitor | CVE-2024-55214No exploit | Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the file downldhtmlx · file explorer · CWE-22 | Medium6.5 | — | 0.5% | Feb 7, 2025 |
19Monitor | CVE-2013-6281Proof of concept | Cross-site scripting (XSS) vulnerability in codebase/spreadsheet.php in the Spreadsheet (dhtmlxSpreadsheet) plugin 2.0 for WordPress allows dhtmlx · dhtmlxspreadsheet · CWE-79 | Medium4.3 | — | 5.2% | Oct 25, 2013 |
- CVE-2026-4155340Plan
Remote Code Execution in PDF Export Module
CriticalCVSS 10.0No exploitEPSS 1%dhtmlx · pdf export moduleMay 15, 2026
- CVE-2026-4155236Monitor
Path Traversal in PDF Export Module
CriticalCVSS 9.2No exploitEPSS 1%dhtmlx · pdf export moduleMay 15, 2026
- CVE-2024-5521326Monitor
Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the File Listin
MediumCVSS 6.5No exploitEPSS 1%dhtmlx · file explorerFeb 7, 2025
- CVE-2024-5521426Monitor
Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the file downl
MediumCVSS 6.5No exploitEPSS 1%dhtmlx · file explorerFeb 7, 2025
- CVE-2013-628119Monitor
Cross-site scripting (XSS) vulnerability in codebase/spreadsheet.php in the Spreadsheet (dhtmlxSpreadsheet) plugin 2.0 for WordPress allows
MediumCVSS 4.3Proof of conceptEPSS 5%dhtmlx · dhtmlxspreadsheetOct 25, 2013