Syncfusion's vulnerability footprint centers on its web and file-handling components across its ASP.NET Core and Node.js platform offerings, with the recurring signal focused on file-path and input-handling weaknesses including path traversal and cross-site scripting. These are structural risks endemic to server-side file-provider and web-rendering components rather than a broad portfolio pattern; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Syncfusion over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26563CRITICAL The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal. As a result, an unauthenticated attacker can: - On Windows, list files in a | Jul 12, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-26564CRITICAL The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal. As a result, an unauthenticated attacker can list files within | Jul 12, 2023 | 9.8 | 27 | NO | NO |
CVE-2025-63260MEDIUM SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-UI Chat message. | Mar 20, 2026 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Syncfusion.
Media articles that mention a CVE ID that affects a product developed by Syncfusion — matched by CVE ID, not by vendor name.