Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Openjsf

First CVE: Jan 23, 2017Active for: 9 yearsTotal CVEs: 19
33.5
VTI Score
Medium

The OpenJS Foundation maintains a portfolio of widely adopted Node.js frameworks and middleware components such as Express, Fastify, and body-parser that underpin numerous web applications and APIs. Vulnerabilities affecting these products center on web application input-handling and server-side code-generation issues, notably cross-site scripting, OS command injection, and prototype pollution, reflecting the exposure surface of JavaScript runtime environments. Current severity, exploitation activity, and product coverage are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Openjsf over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2017
9 years ago
Most Recent CVE
Jul 9, 2026
15 days ago

Products(12 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-25244CRITICAL
WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnera
May 18, 20269.842NONO
CVE-2026-13676HIGH
fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the
Jun 29, 20267.537NONO
CVE-2026-6322HIGH
fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an
May 5, 20267.536NONO
CVE-2026-6321HIGH
fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like r
May 4, 20267.536NONO
CVE-2026-10796HIGH
nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings supplied by the configured Node.js/io.js mirror. Commands such as `nvm install` read the
Jun 4, 20267.533NONO
CVE-2022-24999HIGH
qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be use
Nov 26, 20227.532NONO
CVE-2026-12590MEDIUM
Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or N
Jul 9, 20265.929NONO
CVE-2025-57349HIGH
The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollution due to improper handling of message k
Sep 24, 20257.525NONO
CVE-2024-45590HIGH
body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted pay
Sep 10, 20247.525NONO
CVE-2025-50537MEDIUM
Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/shared/serialization.js. The exploit is triggered via the RuleT
Jan 26, 20265.521NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
47%
47%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.3%)
Network18 (94.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (78.9%)
High4 (21.1%)
Unknown0 (0.0%)
User Interaction
None11 (57.9%)
Unknown0 (0.0%)
Required8 (42.1%)
Privileges Required
Low1 (5.3%)
High0 (0.0%)
None18 (94.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Openjsf.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Openjsf — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Openjsf's Products

View all 4 CNAs →

Top CWEs