jgraph records
3 published records for vendor jgraph.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 66.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-18197No exploit | In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External jgraph · mxgraph · CWE-611 | Critical9.8 | — | 2.9% | Feb 23, 2018 |
24Monitor | CVE-2019-13127No exploit | An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products.draw · draw.io diagrams · CWE-20 | Medium6.1 | — | 1.5% | Jul 1, 2019 |
24Monitor | CVE-2022-40440No exploit | mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function.jgraph · mxgraph · CWE-79 | Medium6.1 | — | 0.6% | Oct 11, 2022 |
- CVE-2017-1819740Plan
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External
CriticalCVSS 9.8No exploitEPSS 3%jgraph · mxgraphFeb 23, 2018
- CVE-2019-1312724Monitor
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products.
MediumCVSS 6.1No exploitEPSS 2%draw · draw.io diagramsJul 1, 2019
- CVE-2022-4044024Monitor
mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function.
MediumCVSS 6.1No exploitEPSS 1%jgraph · mxgraphOct 11, 2022