Datatables is a widely embedded JavaScript table-rendering library whose vulnerability footprint, though narrow in scope, centers on the core datatables.net product and reflects the input-handling and prototype-manipulation surface inherent to client-side DOM manipulation. The durable signal across its disclosures involves cross-site scripting and prototype-pollution weaknesses, patterns typical of libraries that process user-supplied or external data for table construction and display. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Datatables over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23445MEDIUM This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped. | Sep 27, 2021 | 6.1 | 22 | NO | NO |
CVE-2020-28458HIGH All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806. | Dec 16, 2020 | 7.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Datatables.
Media articles that mention a CVE ID that affects a product developed by Datatables — matched by CVE ID, not by vendor name.