Mootools is a compact JavaScript framework and its companion library mootools-more, where the observed vulnerability landscape centers on prototype-pollution weaknesses and denial-of-service conditions rooted in inefficient regular expressions and uncontrolled resource consumption. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mootools over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23432CRITICAL This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge() | Aug 24, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-20088HIGH Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in mootools-more 1.6.0 allows a malicious user to inject properties into Object.prototype. | Apr 23, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-32821HIGH MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Serv | Jan 3, 2023 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mootools.
Media articles that mention a CVE ID that affects a product developed by Mootools — matched by CVE ID, not by vendor name.