Skip to content
Noroxi

plotly records

4 published records for vendor plotly.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

4 records
  • In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.

    CriticalCVSS 9.8No exploitEPSS 1%

    plotly · plotly.jsJan 3, 2024

  • Plotly.js Graphing - Critical - PHP object injection - SA-CONTRIB-2026-050

    HighCVSS 8.1No exploitEPSS 0%

    plotly · plotly.js graphingJul 10, 2026

  • Plotly, Inc.

    MediumCVSS 6.1No exploitEPSS 1%

    plotly · plotly.jsJul 17, 2017

  • Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the packa

    MediumCVSS 5.4Proof of conceptEPSS 1%

    plotly · dashFeb 2, 2024