Ember.js is a focused JavaScript framework for building web applications, with its vulnerability profile concentrated in a single, widely adopted core product. The recurring exposure reflects input-handling challenges inherent to a DOM-manipulation framework, where cross-site scripting weaknesses arise in the templating and component-rendering pipeline. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Emberjs over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0014MEDIUM Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) | Feb 15, 2018 | 5.4 | 19 | NO | NO |
CVE-2014-0013MEDIUM Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) | Feb 15, 2018 | 5.4 | 19 | NO | NO |
CVE-2013-4170MEDIUM In general, Ember.js escapes or strips any user-supplied content before inserting it in strings that will be sent to innerHTML. However, the `tagName` property of an `Ember.View` w | Jun 30, 2022 | 6.1 | 17 | NO | NO |
CVE-2015-1866MEDIUM Cross-site scripting (XSS) vulnerability in Ember.js 1.10.x before 1.10.1 and 1.11.x before 1.11.2. | Sep 20, 2017 | 6.1 | 17 | NO | NO |
CVE-2015-7565MEDIUM Cross-site scripting (XSS) vulnerability in Ember.js 1.8.x through 1.10.x, 1.11.x before 1.11.4, 1.12.x before 1.12.2, 1.13.x before 1.13.12, 2.0.x before 2.0.3, 2.1.x before 2.1.2 | Apr 13, 2017 | 6.1 | 17 | NO | NO |
Cross-site scripting (XSS) vulnerability in the link-to helper in Ember.js 1.2.x before 1.2.2, 1.3.x before 1.3.2, and 1.4.x before 1.4.0-beta.6, when used in non-block form, allow | Feb 27, 2014 | 2.6 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Emberjs.
Media articles that mention a CVE ID that affects a product developed by Emberjs — matched by CVE ID, not by vendor name.