Qooxdoo is a lightweight application framework centered on a single, modestly represented product with presence in web-development tooling and client-side application environments. Its observed vulnerability surface clusters around web-layer input-handling issues, primarily cross-site scripting and path traversal weaknesses characteristic of framework-level exposure to untrusted user input and file-access controls.
The number and severity of CVEs published that impact products developed by Qooxdoo over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-1715MEDIUM Directory traversal vulnerability in framework/source/resource/qx/test/part/delay.php in QooxDoo 1.3 and possibly other versions, as used in eyeOS 2.2 and 2.3, and possibly other p | Apr 18, 2011 | 5.0 | 29 | NO | YES |
CVE-2011-1714MEDIUM Cross-site scripting (XSS) vulnerability in framework/source/resource/qx/test/jsonp_primitive.php in QooxDoo 1.3 and possibly other versions, as used in eyeOS 2.2 and 2.3, and poss | Apr 18, 2011 | 4.3 | 24 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qooxdoo.
Media articles that mention a CVE ID that affects a product developed by Qooxdoo — matched by CVE ID, not by vendor name.