Libxslt
Vendor:
First CVE: Aug 1, 2008 · Active for 17 years
25
Total CVEs
More Total CVEs than 95% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Libxslt over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 2008
17 years ago
Most Recent CVE
Jul 10, 2025
379 days ago
CVE Severity & Scoring
Libxslt25 CVEs
40%
40%
20%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (8.0%)
Network16 (64.0%)
Unknown7 (28.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (60.0%)
High3 (12.0%)
Unknown7 (28.0%)
User Interaction
None12 (48.0%)
Unknown7 (28.0%)
Required6 (24.0%)
Privileges Required
Low2 (8.0%)
High0 (0.0%)
None16 (64.0%)
Unknown7 (28.0%)
Top CVEs
Signals from CVEs in this product scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-30560HIGH Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Aug 3, 2021 | 8.8 | 39 | NO | NO |
CVE-2016-4607CRITICAL libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote a | Jul 22, 2016 | 9.8 | 34 | NO | NO |
CVE-2008-2935HIGH Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in l | Aug 1, 2008 | 7.5 | 34 | NO | YES |
CVE-2016-4610CRITICAL libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote a | Jul 22, 2016 | 9.8 | 33 | NO | NO |
CVE-2019-11068CRITICAL libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead | Apr 10, 2019 | 9.8 | 32 | NO | NO |
CVE-2016-4609CRITICAL libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote a | Jul 22, 2016 | 9.8 | 32 | NO | NO |
CVE-2017-5029HIGH The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, | Apr 24, 2017 | 8.8 | 29 | NO | NO |
CVE-2025-7424HIGH A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This | Jul 10, 2025 | 7.5 | 27 | NO | NO |
CVE-2019-18197HIGH In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certa | Oct 18, 2019 | 7.5 | 26 | NO | NO |
CVE-2016-4608CRITICAL libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote a | Jul 22, 2016 | 9.8 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (25 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.0% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (25 CVEs).
Media Mentions
Signals from CVEs in this product scope (25 CVEs).
Top CNAs Publishing CVEs For Libxslt
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.1.9 | 4 | 5.3 | 5.5% | 0 | 1 |
| 1.1.8 | 4 | 5.3 | 5.5% | 0 | 1 |
| 1.1.7 | 2 | 4.7 | 3.3% | 0 | 0 |
| 1.1.6 | 2 | 4.7 | 3.3% | 0 | 0 |
| 1.1.5 | 2 | 4.7 | 3.3% | 0 | 0 |
| 1.1.4 | 2 | 4.7 | 3.3% | 0 | 0 |
| 1.1.33 | 3 | 6.0 | 5.4% | 0 | 0 |
| 1.1.3 | 2 | 4.7 | 3.3% | 0 | 0 |
| 1.1.29 | 1 | 8.8 | 2.1% | 0 | 0 |
| 1.1.26 | 1 | 5.0 | 4.3% | 0 | 0 |
| 1.1.25 | 1 | 5.0 | 4.3% | 0 | 0 |
| 1.1.24 | 3 | 5.6 | 6.5% | 0 | 1 |
| 1.1.23 | 4 | 5.3 | 5.5% | 0 | 1 |
| 1.1.22 | 4 | 5.3 | 5.5% | 0 | 1 |
| 1.1.21 | 4 | 5.3 | 5.5% | 0 | 1 |
| 1.1.20 | 4 | 5.3 | 5.5% | 0 | 1 |
| 1.1.2 | 2 | 4.7 | 3.3% | 0 | 0 |
| 1.1.19 | 4 | 5.3 | 5.5% | 0 | 1 |
| 1.1.18 | 4 | 5.3 | 5.5% | 0 | 1 |
| 1.1.17 | 4 | 5.3 | 5.5% | 0 | 1 |