Plotly develops web-based visualization and interactive dashboard libraries, principally Plotly.js and Dash, that embed data-rendering functionality across client-side and server-side applications. Its vulnerability footprint reflects the attack surface of browser-driven and web-application contexts, with observed weakness classes centered on improper input neutralization in dynamically generated web content (cross-site scripting) and prototype pollution, both characteristic of JavaScript libraries and interactive web frameworks.
The number and severity of CVEs published that impact products developed by Plotly over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-55810HIGH Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Grap | Jul 10, 2026 | 8.1 | 34 | NO | NO |
CVE-2023-46308CRITICAL In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty. | Jan 3, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-21485MEDIUM Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the package dash before 2.15.0; versions of the p | Feb 2, 2024 | 5.4 | 26 | NO | YES |
CVE-2017-1000006MEDIUM Plotly, Inc. plotly.js versions prior to 1.16.0 are vulnerable to an XSS issue. | Jul 17, 2017 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Plotly.
Media articles that mention a CVE ID that affects a product developed by Plotly — matched by CVE ID, not by vendor name.