MPXJ is a niche Java library for parsing and working with Microsoft Project files, serving a specialized but recurring role in project-management tooling and integrations. Its vulnerability profile centers on resource-exposure and input-handling weakness classes including path traversal, XXE injection, improper file handling, and disclosure of sensitive information—patterns typical of file-parsing libraries that process structured data from untrusted sources. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mpxj over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25020CRITICAL MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components. | Aug 29, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-35460MEDIUM common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations. | Dec 14, 2020 | 5.3 | 20 | NO | NO |
MPXJ is an open source library to read and write project plans from a variety of file formats and databases. On Unix-like operating systems (not Windows or macos), MPXJ's use of `F | Nov 25, 2022 | 3.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mpxj.
Media articles that mention a CVE ID that affects a product developed by Mpxj — matched by CVE ID, not by vendor name.