Dhtmlx develops web-based UI components and widgets such as file explorer and spreadsheet controls that are embedded across web applications, with observed vulnerabilities centered on input-handling and path-boundary weaknesses including path traversal, cross-site scripting, and OS command injection. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dhtmlx over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41553CRITICAL PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. An unauthenticated attacker can | May 15, 2026 | 10.0 | 36 | NO | NO |
CVE-2026-41552HIGH PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated user could craft the html paylo | May 15, 2026 | 7.5 | 29 | NO | NO |
CVE-2013-6281MEDIUM Cross-site scripting (XSS) vulnerability in codebase/spreadsheet.php in the Spreadsheet (dhtmlxSpreadsheet) plugin 2.0 for WordPress allows remote attackers to inject arbitrary web | Oct 25, 2013 | 4.3 | 22 | NO | YES |
CVE-2024-55213MEDIUM Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the File Listing function. | Feb 7, 2025 | 6.5 | 19 | NO | NO |
CVE-2024-55214MEDIUM Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the file download functionality. | Feb 7, 2025 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dhtmlx.
Media articles that mention a CVE ID that affects a product developed by Dhtmlx — matched by CVE ID, not by vendor name.