Plv8 is a PostgreSQL extension that embeds the V8 JavaScript engine, enabling stored procedures and functions written in JavaScript within PostgreSQL databases. The vulnerability footprint is narrow and focused on the plv8 product itself, with observed weaknesses centered on improper exception handling and unexpected return-value validation in the JavaScript-to-SQL bridge layer. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Plv8 over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1713HIGH A user who can create objects in a database with plv8 3.2.1 installed is able to cause deferred triggers to execute as the Superuser during autovacuum.
| Mar 14, 2024 | 7.2 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Plv8.
Media articles that mention a CVE ID that affects a product developed by Plv8 — matched by CVE ID, not by vendor name.