Joget develops a focused low-code application development and workflow platform that spans a narrow product line, with observed vulnerabilities centering on web-application input-handling issues including cross-site scripting and improper formula neutralization in CSV exports. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joget over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14352HIGH In Joget Workflow 6.0.20, CSV Injection, also known as Formula Injection, exists, as demonstrated by jw/web/userview/crm_community/crm_userview_sales/_/account_new with the Account | Jul 28, 2019 | 7.8 | 23 | NO | NO |
CVE-2022-26197MEDIUM Joget DX 7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Datalist table. | Mar 25, 2022 | 5.4 | 22 | NO | NO |
CVE-2022-4560MEDIUM A vulnerability was found in Joget up to 7.0.31. It has been rated as problematic. This issue affects the function getInternalJsCssLib of the file wflow-core/src/main/java/org/joge | Dec 16, 2022 | 6.1 | 21 | NO | NO |
CVE-2022-4859MEDIUM A vulnerability, which was classified as problematic, has been found in Joget up to 7.0.33. This issue affects the function submitForm of the file wflow-core/src/main/java/org/joge | Dec 30, 2022 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joget.
Media articles that mention a CVE ID that affects a product developed by Joget — matched by CVE ID, not by vendor name.