Sencha develops a focused set of web-application frameworks and middleware products, including Connect and Ext JS, that operate in the request-processing layer of browser-based and server applications. Its vulnerability exposure concentrates around web-facing input-handling weaknesses, particularly cross-site scripting and server-side request forgery issues that arise in framework-level request and template handling. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sencha over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8046MEDIUM The getTip() method of Action Columns of Sencha Ext JS 4 to 6 before 6.6.0 is vulnerable to XSS attacks, even when passed HTML-escaped data. This framework brings no built-in XSS p | Jul 5, 2018 | 6.1 | 57 | NO | NO |
CVE-2007-6758HIGH Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0. | Jan 23, 2020 | 7.5 | 24 | NO | NO |
CVE-2013-7370MEDIUM node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware | Dec 11, 2019 | 6.1 | 21 | NO | NO |
CVE-2013-7371MEDIUM node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370) | Dec 11, 2019 | 6.1 | 20 | NO | NO |
CVE-2018-3717MEDIUM connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware. | Jun 7, 2018 | 5.4 | 19 | NO | NO |
CVE-2013-4691MEDIUM Sencha Labs Connect has XSS with connect.methodOverride() | Dec 27, 2019 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sencha.
Media articles that mention a CVE ID that affects a product developed by Sencha — matched by CVE ID, not by vendor name.