Greasemonkey is a browser extension that allows users to run custom scripts on web pages, presenting a narrow but permeable attack surface centered on script-injection and execution contexts. The observed vulnerability profile reflects the userscript engine's role as an interpreter of potentially untrusted code and the complexity of isolating scripts from browser internals and host page contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Greasemonkey over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2455MEDIUM Greasemonkey before 0.3.5 allows remote web servers to (1) read arbitrary files via a GET request to a file:// URL in the GM_xmlhttpRequest API function, (2) list installed scripts | Aug 4, 2005 | 5.0 | 25 | NO | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Greasemonkey.
Media articles that mention a CVE ID that affects a product developed by Greasemonkey — matched by CVE ID, not by vendor name.