Skip to main content

Vendor/product archive

jgraph / mxgraph CVEs

Beta · best-effort

3 CVEs tagged to jgraph / mxgraph1 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2022-40440

Published Oct 12, 2022

mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18197

Published Feb 24, 2018

In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated b…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1