Mootools Project maintains a JavaScript framework library used across web applications for client-side functionality and DOM manipulation. Observed vulnerabilities in this product center on input-handling and validation issues, though the vendor's narrow footprint and focused product scope mean its disclosures carry limited broad-landscape significance. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mootools Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23432CRITICAL This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge() | Aug 24, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-20088HIGH Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in mootools-more 1.6.0 allows a malicious user to inject properties into Object.prototype. | Apr 23, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-32821HIGH MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Serv | Jan 3, 2023 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mootools Project.
Media articles that mention a CVE ID that affects a product developed by Mootools Project — matched by CVE ID, not by vendor name.