Electron

Vendor:

First CVE: Mar 7, 2018 · Active for 8 years

39
Total CVEs
More Total CVEs than 97% of tracked products
6.5
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Electron over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 7, 2018
8 years ago
Most Recent CVE
Apr 7, 2026
108 days ago

CVE Severity & Scoring

Electron39 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local8 (20.5%)
Network31 (79.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low32 (82.1%)
High7 (17.9%)
Unknown0 (0.0%)
User Interaction
None26 (66.7%)
Unknown0 (0.0%)
Required13 (33.3%)
Privileges Required
Low9 (23.1%)
High2 (5.1%)
None28 (71.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (39 CVEs).

39 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a Web
Aug 23, 20188.142NOYES
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and 41.0.0, the nodeIntegrationInW
Apr 4, 20269.836NONO
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls w
Apr 7, 20268.834NONO
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that allow
Apr 4, 20268.833NONO
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that regis
Apr 4, 20268.833NONO
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented
Apr 4, 20268.832NONO
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 39.8.1, 40.7.0, and 41.0.0, apps that use offscreen render
Apr 4, 20268.131NONO
Missing Authorization vulnerability in Ninetheme Electron electron allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Electron: from n/a thr
Jan 22, 20268.831NONO
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on macOS, app.m
Apr 4, 20267.830NONO
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Windows, app
Apr 4, 20267.830NONO

Exploit Exposure

Signals from CVEs in this product scope (39 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.6% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (39 CVEs).

Media Mentions

Signals from CVEs in this product scope (39 CVEs).

Top CNAs Publishing CVEs For Electron

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.3.015.60.7%00
9.2.115.60.7%00
9.2.015.60.7%00
9.1.215.60.7%00
9.1.115.60.7%00
9.1.015.60.7%00
9.0.615.60.7%00
9.0.515.60.7%00
9.0.415.60.7%00
9.0.315.60.7%00
9.0.215.60.7%00
9.0.115.60.7%00
9.0.067.51.0%00
8.5.115.60.7%00
8.5.015.60.7%00
8.4.115.60.7%00
8.4.015.60.7%00
8.3.415.60.7%00
8.3.315.60.7%00
8.3.215.60.7%00