plotly records
4 published records for vendor plotly.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-46308No exploit | In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.plotly · plotly.js · CWE-1321 | Critical9.8 | — | 0.9% | Jan 3, 2024 |
32Monitor | CVE-2026-55810No exploit | Plotly.js Graphing - Critical - PHP object injection - SA-CONTRIB-2026-050plotly · plotly.js graphing · CWE-915 | High8.1 | — | 0.4% | Jul 10, 2026 |
24Monitor | CVE-2017-1000006No exploit | Plotly, Inc.plotly · plotly.js · CWE-79 | Medium6.1 | — | 0.9% | Jul 17, 2017 |
21Monitor | CVE-2024-21485Proof of concept | Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the packaplotly · dash · CWE-79 | Medium5.4 | — | 1.5% | Feb 2, 2024 |
- CVE-2023-4630839Monitor
In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.
CriticalCVSS 9.8No exploitEPSS 1%plotly · plotly.jsJan 3, 2024
- CVE-2026-5581032Monitor
Plotly.js Graphing - Critical - PHP object injection - SA-CONTRIB-2026-050
HighCVSS 8.1No exploitEPSS 0%plotly · plotly.js graphingJul 10, 2026
- CVE-2017-100000624Monitor
Plotly, Inc.
MediumCVSS 6.1No exploitEPSS 1%plotly · plotly.jsJul 17, 2017
- CVE-2024-2148521Monitor
Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the packa
MediumCVSS 5.4Proof of conceptEPSS 1%plotly · dashFeb 2, 2024