CVEs (26)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
OS Command Injection in GitHub repository jgraph/drawio prior to 21.5.0. |
OS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0. |
Cross-site Scripting (XSS) - Reflected in GitHub repository jgraph/drawio prior to 21.6.3. |
Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3. |
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 21.2.8. |
Cross-site Scripting (XSS) - DOM in GitHub repository jgraph/drawio prior to 20.5.2. |
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1. |
OS Command Injection in GitHub repository jgraph/drawio prior to 20.3.0. |
Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0. |
Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0. |
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.2.8. |
Improper Access Control in GitHub repository jgraph/drawio prior to 20.2.8. |
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 19.0.2. |
Code Injection in GitHub repository jgraph/drawio prior to 19.0.2. |
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2. |
Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.8. |
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 18.0.4. |
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7. |
Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.7. |
Improper Input Validation in GitHub repository jgraph/drawio prior to 18.0.6. |