Zeroclipboard Project maintains a lightweight client-side library that facilitates clipboard interactions in web applications, presenting a narrow but notably deployed JavaScript component used across web-facing systems. The observed vulnerability signal centers on cross-site scripting weaknesses, reflecting the injection risks inherent to a library that mediates user input and clipboard data flow in the browser context. Current exposure levels and recent disclosures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zeroclipboard Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6550MEDIUM Cross-site scripting (XSS) vulnerability in ZeroClipboard before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via "the clipText returned from the flash obje | Apr 2, 2013 | 4.3 | 26 | NO | YES |
CVE-2013-1808MEDIUM Cross-site scripting (XSS) vulnerability in ZeroClipboard.swf and ZeroClipboard10.swf in ZeroClipboard before 1.0.8, as used in em-shorty, RepRapCalculator, Fulcrum, Django, aCMS, | Apr 2, 2013 | 4.3 | 20 | NO | NO |
CVE-2014-1869MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in ZeroClipboard.swf in ZeroClipboard before 1.3.2, as maintained by Jon Rohan and James M. Greene, allow remote attackers to in | Feb 8, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zeroclipboard Project.
Media articles that mention a CVE ID that affects a product developed by Zeroclipboard Project — matched by CVE ID, not by vendor name.