Morris.Js Project maintains a lightweight JavaScript charting library focused on data visualization across web applications, with its vulnerability exposure centered on the core Morris.js product. The observed weakness class involves improper input neutralization during web page generation, reflecting the characteristic risks of client-side rendering libraries that process untrusted data into DOM structures. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Morris.Js Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-16022MEDIUM Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not escaped in versions 0.5.0 and earlier. If control over the labe | Jun 4, 2018 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Morris.Js Project.
Media articles that mention a CVE ID that affects a product developed by Morris.Js Project — matched by CVE ID, not by vendor name.