Ag Grid develops a narrowly focused set of data-visualization and grid-display libraries for web applications, a niche but embedded component across various frontend ecosystems. The observed vulnerability surface for this vendor remains modest and does not yet point to a durable pattern of weakness classes; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ag Grid over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-38996CRITICAL ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.mergeDeep function. This vulnerability allows attackers to execu | Jul 1, 2024 | 9.8 | 27 | NO | NO |
CVE-2017-16009MEDIUM ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angular Expressions, if AngularJS is used in combination with ag- | Jun 4, 2018 | 6.1 | 21 | NO | NO |
CVE-2024-39001MEDIUM ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code | Jul 1, 2024 | 6.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ag Grid.
Media articles that mention a CVE ID that affects a product developed by Ag Grid — matched by CVE ID, not by vendor name.