Cordova

Vendor:

First CVE: Mar 3, 2014 · Active for 12 years

18
Total CVEs
More Total CVEs than 93% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 25% of tracked products
5.6%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Cordova over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 3, 2014
12 years ago
Most Recent CVE
Feb 16, 2021
1,984 days ago

CVE Severity & Scoring

Cordova18 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local4 (22.2%)
Network5 (27.8%)
Unknown9 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (38.9%)
High2 (11.1%)
Unknown9 (50.0%)
User Interaction
None6 (33.3%)
Unknown9 (50.0%)
Required3 (16.7%)
Privileges Required
Low2 (11.1%)
High0 (0.0%)
None7 (38.9%)
Unknown9 (50.0%)

Top CVEs

Signals from CVEs in this product scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In
Feb 16, 20217.896YESYES
The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from C
Oct 30, 20179.834NONO
ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0.4.2 for iOS and the File-Transfer plugin for iOS from Cordov
Oct 30, 20177.528NONO
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote attackers to bypass a whitelist
Mar 3, 20147.527NONO
Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()
May 9, 20177.526NONO
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an event-based bridge via a crafted
Mar 3, 20147.524NONO
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an event-based bridge via a crafted
Mar 3, 20147.523NONO
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier on Windows Phone 7 and 8 do not properly restrict navigation events, which allows remote attackers to bypass i
Mar 3, 20147.522NONO
After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, the scripts will fetch Gradle on the first build. However, sin
Feb 1, 20187.421NONO
Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by leveraging unspecified methods.
May 9, 20165.321NONO

Exploit Exposure

Signals from CVEs in this product scope (18 CVEs).

CISA KEV
1 CVE
5.6% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.6% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (18 CVEs).

Media Mentions

Signals from CVEs in this product scope (18 CVEs).

Top CNAs Publishing CVEs For Cordova

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.1.013.30.7%00
4.0.115.35.9%00
4.0.015.35.9%00
3.5.024.34.4%00
3.3.047.510.0%00
3.2.047.510.0%00
3.1.047.510.0%00
3.0.047.510.0%00
10.0.017.890.2%11