Colorbox Project develops a lightweight, focused lightbox jQuery plugin with a comparatively small vulnerability surface area that centers on web-based modal and image-display functionality. The recurring exposure reflects application-layer concerns—improper access control and cross-site scripting vulnerabilities in web presentation logic—typical of client-side dialog and content-rendering libraries. Live severity, exploitation, and current CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Colorbox Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-58591MEDIUM Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox | Jul 10, 2026 | 5.4 | 27 | NO | NO |
CVE-2025-3900MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS).This issue affects Colorbox: | Apr 23, 2025 | 6.1 | 18 | NO | NO |
The Colorbox module 7.x-2.x before 7.x-2.10 for Drupal allows remote authenticated users with certain permissions to bypass intended access restrictions and "add unexpected content | Oct 26, 2015 | 3.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Colorbox Project.
Media articles that mention a CVE ID that affects a product developed by Colorbox Project — matched by CVE ID, not by vendor name.