Ionicframework's vulnerability footprint is concentrated in mobile application development components, primarily the Ionic WebView for iOS and related keychain integration functionality. The durable signal centers on file-system access control and information-disclosure weaknesses, including path-traversal conditions and sensitive-data logging issues that can arise in mobile middleware handling local storage and credentials. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ionicframework over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000123CRITICAL Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Through Log Files (CWE-532) vulnerability in | Mar 13, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-16202HIGH Directory traversal vulnerability in cordova-plugin-ionic-webview versions prior to 2.2.0 (not including 2.0.0-beta.0, 2.0.0-beta.1, 2.0.0-beta.2, and 2.1.0-0) allows remote attack | Jan 9, 2019 | 8.6 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ionicframework.
Media articles that mention a CVE ID that affects a product developed by Ionicframework — matched by CVE ID, not by vendor name.