Tinyxml2 is a lightweight XML parsing library with a narrow product footprint but wide embedding across applications and systems that consume XML data. Its disclosed vulnerabilities center on parser robustness issues, including reachable assertions and out-of-bounds reads, reflecting the input-validation demands inherent to parsing untrusted markup. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tinyxml2 Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11210CRITICAL TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::Parse function in libtinyxml2.so. NOTE: The tinyxml2 developers have determined that the reported overflow is d | May 16, 2018 | 9.8 | 29 | NO | NO |
CVE-2024-50615MEDIUM TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef. | Oct 27, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-50614MEDIUM TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef. | Oct 27, 2024 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tinyxml2 Project.
Media articles that mention a CVE ID that affects a product developed by Tinyxml2 Project — matched by CVE ID, not by vendor name.