Northwestern's vulnerability profile centers on TimelineJS, a web-based timeline-visualization library deployed across educational and public-facing projects. The durable signal reflects the product's browser-side role and recurring input-handling weaknesses, particularly cross-site scripting vulnerabilities in page-generation logic. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Northwestern over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15092MEDIUM In TimelineJS before version 3.7.0, some user data renders as HTML. An attacker could implement an XSS exploit with maliciously crafted content in a number of data fields. This ris | Jul 9, 2020 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Northwestern.
Media articles that mention a CVE ID that affects a product developed by Northwestern — matched by CVE ID, not by vendor name.