VYPR

Mxgraph

by Jgraph

Source repositories

CVEs (3)

  • CVE-2017-18197CriFeb 24, 2018
    risk 0.57cvss 9.8epss 0.03

    In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.

  • CVE-2022-40440MedOct 12, 2022
    risk 0.40cvss 6.1epss 0.01

    mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function.

  • CVE-2019-13127MedJul 1, 2019
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs…