Mxgraph

Vendor:

First CVE: Feb 24, 2018 · Active for 8 years

3
Total CVEs
More Total CVEs than 64% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Mxgraph over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 24, 2018
8 years ago
Most Recent CVE
Oct 12, 2022
1,381 days ago

CVE Severity & Scoring

Mxgraph3 CVEs
All CVEs352,231 CVEs
MediumCritical
Attack Vector
Local0 (0.0%)
Network3 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (33.3%)
Unknown0 (0.0%)
Required2 (66.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (3 CVEs).

3 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by
Feb 24, 20189.832NONO
mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function.
Oct 12, 20226.123NONO
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization o
Jul 1, 20196.121NONO

Exploit Exposure

Signals from CVEs in this product scope (3 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (3 CVEs).

Media Mentions

Signals from CVEs in this product scope (3 CVEs).

Top CNAs Publishing CVEs For Mxgraph

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.2.216.10.6%00