Plug Project maintains a narrowly scoped product focused on web framework and application development, with a vulnerability history centered on data-handling and serialization issues. The observed weakness classes—deserialization of untrusted data, improper input validation, and injection flaws—reflect risks common to server-side processing and downstream component interaction. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Plug Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1000053HIGH Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session. | Jul 17, 2017 | 8.1 | 22 | NO | NO |
CVE-2018-1000883MEDIUM Elixir Plug Plug version All contains a Header Injection vulnerability in Connection that can result in Given a cookie value, Headers can be added. This attack appear to be exploit | Dec 20, 2018 | 6.5 | 21 | NO | NO |
CVE-2017-1000052HIGH Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetype restrictions. | Jul 17, 2017 | 7.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Plug Project.
Media articles that mention a CVE ID that affects a product developed by Plug Project — matched by CVE ID, not by vendor name.