Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Uri.Js Project

First CVE: Dec 31, 2020Active for: 6 yearsTotal CVEs: 8

Uri.js is a JavaScript URI parsing and manipulation library with a narrow product scope but significant presence in the web application supply chain, where a flaw can propagate across dependent projects. Its vulnerability profile centers on input-validation weaknesses including improper URL parsing, open redirects, and authorization-bypass conditions that are inherent to URI-handling logic. Defenders should audit downstream applications that bundle this library and prioritize updates when available; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
2.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Uri.Js Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2020
5 years ago
Most Recent CVE
Apr 5, 2022
1,571 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-27516HIGH
URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
Feb 22, 20217.525NONO
CVE-2022-0613MEDIUM
Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.
Feb 16, 20226.524NONO
CVE-2022-0868MEDIUM
Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.
Mar 6, 20226.123NONO
CVE-2021-3647MEDIUM
URI.js is vulnerable to URL Redirection to Untrusted Site
Jul 16, 20216.122NONO
CVE-2020-26291MEDIUM
URI.js is a javascript URL mutation library (npm package urijs). In URI.js before version 1.19.4, the hostname can be spoofed by using a backslash (`\`) character followed by an at
Dec 31, 20206.522NONO
CVE-2022-1243MEDIUM
CRHTLF can lead to invalid protocol extraction potentially leading to XSS in GitHub repository medialize/uri.js prior to 1.19.11.
Apr 5, 20226.120NONO
CVE-2022-1233MEDIUM
URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11.
Apr 4, 20226.117NONO
CVE-2022-24723MEDIUM
URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This
Mar 3, 20225.316NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
88%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (50.0%)
Unknown0 (0.0%)
Required4 (50.0%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None7 (87.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Uri.Js Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Uri.Js Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Uri.Js Project's Products

View all 3 CNAs →

Top CWEs