Bluespire's vulnerability footprint centers on its Aurelia web framework and related path-handling components, with observed weaknesses clustering around client-side input handling and object-model manipulation. The recurring signal spans cross-site scripting and prototype-pollution vulnerabilities, which are characteristic of JavaScript framework codebases where user input flows through templating and prototype-chain operations. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bluespire over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41097HIGH aurelia-path is part of the Aurelia platform and contains utilities for path manipulation. There is a prototype pollution vulnerability in aurelia-path before version 1.1.7. The vu | Sep 27, 2021 | 7.5 | 37 | NO | YES |
CVE-2019-10062MEDIUM The HTMLSanitizer class in html-sanitizer.ts in all released versions of the Aurelia framework 1.x repository is vulnerable to XSS. The sanitizer only attempts to filter SCRIPT ele | May 13, 2021 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bluespire.
Media articles that mention a CVE ID that affects a product developed by Bluespire — matched by CVE ID, not by vendor name.