The Sonar Wrapper Project maintains a focused wrapper utility designed to support SonarQube integration and automation, representing a narrow component in the code-quality and continuous-integration ecosystem. Vulnerabilities associated with this vendor center on its wrapper product and merit monitoring as part of broader SonarQube-dependent toolchain assessments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sonar Wrapper Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-28443CRITICAL This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js. | Jul 25, 2022 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sonar Wrapper Project.
Media articles that mention a CVE ID that affects a product developed by Sonar Wrapper Project — matched by CVE ID, not by vendor name.