Amcharts provides charting and visualization libraries deployed in web applications, with its disclosed vulnerabilities centered on cross-site scripting flaws arising from improper input neutralization in web page generation. This compact vendor profile reflects the attack surface typical of client-side graphical components; current CVE counts, severity, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Amcharts over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36405MEDIUM Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in amCharts: Charts and Maps plugin <= 1.4 at WordPress. | Aug 23, 2022 | 5.4 | 19 | NO | NO |
CVE-2024-8622MEDIUM The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_javascript' parameter in all versions up to, and including, 1.4 | Sep 12, 2024 | 6.1 | 18 | NO | NO |
CVE-2012-1303MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in amCharts Flash 1 allow remote attackers to inject arbitrary web script or HTML via the (1) data_file or (2) settings_file par | Dec 28, 2014 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Amcharts.
Media articles that mention a CVE ID that affects a product developed by Amcharts — matched by CVE ID, not by vendor name.