Javamelody is a monitoring and profiling library for Java applications that provides runtime visibility into application performance and behavior, with its vulnerability profile centered on a single focused product. The recurring weaknesses—cross-site scripting in web page generation and improper XML external entity handling—reflect the library's role in exposing application metrics through web-based dashboards and its need to safely process external inputs. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Javamelody Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15531CRITICAL JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java. | Sep 26, 2018 | 9.8 | 44 | NO | NO |
CVE-2018-12432MEDIUM JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI. | Jun 14, 2018 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Javamelody Project.
Media articles that mention a CVE ID that affects a product developed by Javamelody Project — matched by CVE ID, not by vendor name.