Jgraph maintains mxGraph, a JavaScript diagramming library widely embedded in web applications for visualization and editing workflows. The durable signal in its vulnerability profile centers on web-layer input-handling issues, including cross-site scripting, input validation gaps, and XML external entity processing, which reflect the exposure surface inherent to a client-side graphics and parsing component. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jgraph over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-18197CRITICAL In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by | Feb 24, 2018 | 9.8 | 32 | NO | NO |
CVE-2022-40440MEDIUM mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function. | Oct 12, 2022 | 6.1 | 23 | NO | NO |
CVE-2019-13127MEDIUM An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization o | Jul 1, 2019 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jgraph.
Media articles that mention a CVE ID that affects a product developed by Jgraph — matched by CVE ID, not by vendor name.