Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Plantuml

First CVE: Apr 15, 2022Active for: 4 yearsTotal CVEs: 5

PlantUML is a widely embedded diagram-as-code tool used across documentation, CI/CD pipelines, and web-based rendering systems, creating exposure in both server-side processing and client-facing contexts. Its observed vulnerabilities concentrate on input-handling and access-control weaknesses—notably cross-site scripting, server-side request forgery, and improper access control—reflecting the parsing demands and network exposure inherent to a rendering engine that accepts and processes untrusted markup. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
5
Total CVEs
More Total CVEs than 83% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Plantuml over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 15, 2022
4 years ago
Most Recent CVE
Jan 16, 2026
190 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-3432CRITICAL
Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9.
Jun 27, 202310.030NONO
CVE-2022-1379CRITICAL
URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security p
May 14, 20229.128NONO
CVE-2026-0858MEDIUM
Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagra
Jan 16, 20266.122NONO
CVE-2023-3431MEDIUM
Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.
Jun 27, 20235.318NONO
CVE-2022-1231MEDIUM
XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual cont
Apr 15, 20226.117NONO
View all 5 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products5 CVEs
60%
40%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (60.0%)
Unknown0 (0.0%)
Required2 (40.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Plantuml.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Plantuml — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Plantuml's Products

View all 2 CNAs →

Top CWEs