VYPR
Medium severity6.1NVD Advisory· Published Jul 1, 2019· Updated Jun 17, 2026

CVE-2019-13127

CVE-2019-13127

Description

An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs.js.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mxgraphnpm
< 4.0.14.0.1

Affected products

4
  • cpe:2.3:a:draw:draw.io_diagrams:*:*:*:*:*:confluence:*:*
    Range: <8.3.14
  • cpe:2.3:a:jgraph:mxgraph:*:*:*:*:*:*:*:*
    Range: <=4.0.0
  • mxGraph/draw.io Diagrams plugin for Confluencedescription
  • ghsa-coords
    Range: < 4.0.1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.