Selenium is a widely used browser automation framework with a distributed architecture centered on Selenium Grid, where the reported vulnerability surface reflects its role in web testing and remote-browser execution. The observed weaknesses cluster around web-application input handling and request validation—cross-site scripting, cross-site request forgery, and NULL-pointer conditions—issues characteristic of frameworks that interact with untrusted browser content and coordinate distributed test agents. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Selenium over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28108HIGH Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-urlencoded, multipart/form-data, and text/plain. | Apr 19, 2022 | 8.8 | 39 | NO | YES |
CVE-2022-28109HIGH Selenium Selenium Grid (formerly Selenium Standalone Server) Fixed in 4.0.0-alpha-7 is affected by: DNS rebinding. The impact is: execute arbitrary code (remote). The component is: | Apr 15, 2022 | 8.8 | 28 | NO | NO |
CVE-2023-5590HIGH NULL Pointer Dereference in GitHub repository seleniumhq/selenium prior to 4.14.0. | Oct 15, 2023 | 7.5 | 21 | NO | NO |
CVE-2020-23452MEDIUM A cross-site scripting (XSS) vulnerability in Selenium Grid v3.141.59 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the hub paramete | Jul 5, 2023 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Selenium.
Media articles that mention a CVE ID that affects a product developed by Selenium — matched by CVE ID, not by vendor name.