The Theia XML Extension Project provides an XML editing and validation extension for the Theia IDE platform, a focused developer-tooling component with a modest vulnerability footprint. Its disclosed vulnerabilities center on path-traversal and XML external entity reference weaknesses, which are characteristic risks in file-handling and document-processing contexts.
The number and severity of CVEs published that impact products developed by Theia Xml Extension Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-18213HIGH XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows XXE via a crafted | Oct 23, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-18212MEDIUM XMLLanguageService.java in XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other product | Oct 23, 2019 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Theia Xml Extension Project.
Media articles that mention a CVE ID that affects a product developed by Theia Xml Extension Project — matched by CVE ID, not by vendor name.