Yworks develops the yEd graph-editing and visualization product, a specialized tool for diagramming and layout that occupies a narrower security footprint than mainstream software platforms. The vendor's vulnerability profile concentrates on XML-processing weaknesses, including improper XML external entity restrictions and XML injection flaws, which reflect the document-handling and parsing demands of a structured graphics application. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yworks over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25216CRITICAL yWorks yEd Desktop before 3.20.1 allows code execution via an XSL Transformation when using an XML file in conjunction with a custom stylesheet. | Sep 17, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-25215CRITICAL yWorks yEd Desktop before 3.20.1 allows XXE attacks via an XML or GraphML document. | Sep 17, 2020 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yworks.
Media articles that mention a CVE ID that affects a product developed by Yworks — matched by CVE ID, not by vendor name.