Prototype.js is a JavaScript framework library that despite its narrow product scope has achieved significant historical adoption across web applications, making vulnerabilities in the library relevant to a broad downstream ecosystem. The framework's disclosed weaknesses cluster around authorization and input-handling gaps, reflecting the access-control and parsing demands of a DOM-manipulation library embedded in client-side code. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Prototypejs over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-7220HIGH Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors. | Sep 13, 2009 | 7.5 | 29 | NO | NO |
CVE-2020-27511HIGH An issue was discovered in the stripTags and unescapeHTML components in Prototype 1.7.3 where an attacker can cause a Regular Expression Denial of Service (ReDOS) through stripping | Jun 21, 2021 | 7.5 | 23 | NO | NO |
CVE-2007-2383MEDIUM The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers | Apr 30, 2007 | 5.0 | 16 | NO | NO |
CVE-2020-7993MEDIUM Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a modified email ID field. | Feb 3, 2020 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Prototypejs.
Media articles that mention a CVE ID that affects a product developed by Prototypejs — matched by CVE ID, not by vendor name.