Client's vulnerability profile centers on JointJS, a JavaScript diagramming and visualization library used in web-based applications. The durable signal reflects type-confusion weaknesses in client-side code, a class of flaw that arises from permissive JavaScript typing in data-handling and serialization contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Client over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23444CRITICAL This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the path parameter are arra | Sep 21, 2021 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Client.
Media articles that mention a CVE ID that affects a product developed by Client — matched by CVE ID, not by vendor name.