CVEs we hold for Jgraph/drawio
Records whose assigning authority named Jgraph/drawio as the affected vendor. Newest identifiers first, capped at 200.
CVE-2023-3973Cross-site Scripting (XSS) - Reflected in jgraph/drawiojgraph/drawio CVE-2023-3026Cross-site Scripting (XSS) - Stored in jgraph/drawiojgraph/drawio CVE-2022-3873Cross-site Scripting (XSS) - DOM in jgraph/drawiojgraph/drawio CVE-2022-3223Cross-site Scripting (XSS) - Stored in jgraph/drawiojgraph/drawio CVE-2022-3148Cross-site Scripting (XSS) - Generic in jgraph/drawiojgraph/drawio CVE-2022-3138Cross-site Scripting (XSS) - Generic in jgraph/drawiojgraph/drawio CVE-2022-3127Cross-site Scripting (XSS) - Stored in jgraph/drawiojgraph/drawio CVE-2022-3065Improper Access Control in jgraph/drawiojgraph/drawio CVE-2022-2015Cross-site Scripting (XSS) - Stored in jgraph/drawiojgraph/drawio CVE-2022-1815Exposure of Sensitive Information to an Unauthorized Actor in jgraph/drawiojgraph/drawio CVE-2022-1784Server-Side Request Forgery (SSRF) in jgraph/drawiojgraph/drawio CVE-2022-1774Exposure of Sensitive Information to an Unauthorized Actor in jgraph/drawiojgraph/drawio CVE-2022-1767Server-Side Request Forgery (SSRF) in jgraph/drawiojgraph/drawio CVE-2022-1730Cross-site Scripting (XSS) - Stored in jgraph/drawiojgraph/drawio CVE-2022-1727Improper Input Validation in jgraph/drawiojgraph/drawio CVE-2022-1723Server-Side Request Forgery (SSRF) in jgraph/drawiojgraph/drawio CVE-2022-1722SSRF in editor's proxy via IPv6 link-local address in jgraph/drawiojgraph/drawio CVE-2022-1721Path Traversal in WellKnownServlet in jgraph/drawiojgraph/drawio CVE-2022-1711Server-Side Request Forgery (SSRF) in jgraph/drawiojgraph/drawio CVE-2022-1575Arbitrary Code Execution through Sanitizer Bypass in jgraph/drawiojgraph/drawio 26 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.