Highcharts is a widely embedded JavaScript charting library used across web applications to render data visualizations, and its vulnerability exposure centers on the product itself through application-layer input-handling issues including cross-site scripting and regular-expression parsing defects. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Highcharts over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20801HIGH In js/parts/SvgRenderer.js in Highcharts JS before 6.1.0, the use of backtracking regular expressions permitted an attacker to conduct a denial of service attack against the SVGRen | Mar 14, 2019 | 7.5 | 26 | NO | NO |
CVE-2021-29489MEDIUM Highcharts JS is a JavaScript charting library based on SVG. In Highcharts versions 8 and earlier, the chart options structure was not systematically filtered for XSS vectors. The | May 5, 2021 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Highcharts.
Media articles that mention a CVE ID that affects a product developed by Highcharts — matched by CVE ID, not by vendor name.