Vega Project maintains a specialized financial-market data and visualization platform that, despite a narrow product footprint, occupies a prominent role in institutional trading infrastructure. Its vulnerabilities skew toward serious outcomes and recur through web-application weakness classes, principally cross-site scripting and prototype pollution, that reflect the exposure of browser-facing interfaces to untrusted market data and user input. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vega Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3323HIGH An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes. | Apr 28, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-65110CRITICAL Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Prior to versions 6.1.2 and 5.6.3, applications meeting t | Jan 5, 2026 | 9.3 | 28 | NO | NO |
CVE-2020-26296HIGH Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega in an npm package. In Vega before version 5.17.3 the | Dec 30, 2020 | 8.7 | 26 | NO | NO |
CVE-2023-26487MEDIUM Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs.`lassoAppend' function accepts 3 arguments and internally | Mar 4, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-26486MEDIUM Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. The Vega `scale` expression function has the ability to c | Mar 4, 2023 | 6.1 | 21 | NO | NO |
CVE-2025-26619MEDIUM Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In `vega` 5.30.0 and lower and in `vega-functions` 5.15.0 | Mar 27, 2025 | 6.1 | 18 | NO | NO |
CVE-2019-10806MEDIUM vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object | Mar 9, 2020 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vega Project.
Media articles that mention a CVE ID that affects a product developed by Vega Project — matched by CVE ID, not by vendor name.