Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Electronjs

First CVE: Mar 7, 2018Active for: 8 yearsTotal CVEs: 41
45.0
VTI Score
High

Electron is a framework for building cross-platform desktop applications using web technologies, and vulnerabilities affecting it propagate across a broad ecosystem of dependent applications built on the platform despite a narrow direct product list. Flaws in Electron itself and applications built atop it skew toward serious outcomes, with a meaningful share reaching critical severity, driven by the framework's privileged access to system resources and the complexity of sandboxing enforcement in chromium-based runtimes. The recurring vulnerability classes center on resource-exposure issues, use-after-free conditions, input-validation gaps, and OS command injection, reflecting both the memory-safety demands of native code layers and the boundary between web-accessible surfaces and host-system capabilities. Defenders should treat Electron framework advisories as broadly relevant and monitor applications built on the platform for upstream patches, since remediation often requires coordinated updates across the application layer. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
41
Total CVEs
More Total CVEs than 98% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Electronjs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 7, 2018
8 years ago
Most Recent CVE
Apr 7, 2026
108 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (41 CVEs).

41 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-15685HIGH
GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a Web
Aug 23, 20188.142NOYES
CVE-2026-34775CRITICAL
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and 41.0.0, the nodeIntegrationInW
Apr 4, 20269.836NONO
CVE-2026-34765HIGH
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls w
Apr 7, 20268.834NONO
CVE-2026-34772HIGH
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that allow
Apr 4, 20268.833NONO
CVE-2026-34771HIGH
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that regis
Apr 4, 20268.833NONO
CVE-2026-34769HIGH
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented
Apr 4, 20268.832NONO
CVE-2026-34774HIGH
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 39.8.1, 40.7.0, and 41.0.0, apps that use offscreen render
Apr 4, 20268.131NONO
CVE-2025-5805HIGH
Missing Authorization vulnerability in Ninetheme Electron electron allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Electron: from n/a thr
Jan 22, 20268.831NONO
CVE-2026-34779HIGH
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on macOS, app.m
Apr 4, 20267.830NONO
CVE-2026-34768HIGH
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Windows, app
Apr 4, 20267.830NONO
View all 41 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products41 CVEs
32%
49%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (19.5%)
Network33 (80.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low34 (82.9%)
High7 (17.1%)
Unknown0 (0.0%)
User Interaction
None26 (63.4%)
Unknown0 (0.0%)
Required15 (36.6%)
Privileges Required
Low10 (24.4%)
High2 (4.9%)
None29 (70.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (41 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Electronjs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Electronjs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Electronjs's Products

View all 4 CNAs →

Top CWEs