Plot maintains the Plotly visualization library, a widely embedded charting and graphing component that powers interactive data displays across web applications and analytical platforms. The recurring vulnerability signal centers on cross-site scripting arising from improper input neutralization during web page generation, reflecting the library's role in rendering user-supplied data as interactive web content. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Plot over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-9347MEDIUM The wp-plotly plugin before 1.0.3 for WordPress has XSS by authors. | Aug 27, 2019 | 6.1 | 17 | NO | NO |
CVE-2015-5484MEDIUM Cross-site scripting (XSS) vulnerability in the Plotly plugin before 1.0.3 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via a post. | Jan 15, 2020 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Plot.
Media articles that mention a CVE ID that affects a product developed by Plot — matched by CVE ID, not by vendor name.