Diffplug's vulnerability footprint centers on a collection of Eclipse development tools and plugins, including the C/C++ Development Toolkit, Groovy support, and Web Tools Platform, which serve as extensions to the Eclipse IDE. The observed weakness classes—path traversal, XML external entity injection, and improper resource transfer between trust boundaries—reflect input handling and resource management issues common to development tooling that processes user-supplied and external configuration or source material. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Diffplug over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26049HIGH This affects the package com.diffplug.gradle:goomph before 3.37.2. It allows a malicious zip file to potentially break out of the expected destination directory, writing contents i | Sep 11, 2022 | 8.8 | 29 | NO | NO |
CVE-2019-10753MEDIUM In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all versions prior to version 3.0.1 for eclipse-groovy, Spotless wa | Sep 5, 2019 | 5.9 | 21 | NO | NO |
CVE-2019-9843HIGH In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over both HTTP and HTTPS and didn't | Jun 28, 2019 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Diffplug.
Media articles that mention a CVE ID that affects a product developed by Diffplug — matched by CVE ID, not by vendor name.