← Back

Plantuml

plantuml

5 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Plantuml
plantuml

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Plantuml
1Plantuml
Apr 29, 2026
Jan 16, 2026
2.0 LOW· v4
6.1 MEDIUM· v3
N/A· v2
Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams. As a result, a crafted PlantUML diag...Show more
Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams. As a result, a crafted PlantUML diagram can inject malicious JavaScript into generated SVG output, leading to arbitrary script execution in the context of applications that render the SVG.Show less
2Fedoraproject
Plantuml
2Fedora
Plantuml
Nov 21, 2024
Jun 27, 2023
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9.
2Fedoraproject
Plantuml
2Fedora
Plantuml
Nov 21, 2024
Jun 27, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.
2Fedoraproject
Plantuml
2Fedora
Plantuml
Nov 21, 2024
May 14, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request...Show more
URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal resources/servers or sending requests to third party servers.Show less
2Fedoraproject
Plantuml
2Fedora
Plantuml
Nov 21, 2024
Apr 15, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets t...Show more
XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example in desktop applications. Web based applications are the ones most affected. Since the SVG format allows clickable links in diagrams, it is commonly used in plugins for web based projects (like the Confluence plugin, etc. see https://plantuml.com/de/running).Show less