vciy

CVEs we hold for Jgraph/drawio

Records whose assigning authority named Jgraph/drawio as the affected vendor. Newest identifiers first, capped at 200.

CVE-2023-3975OS Command Injection in jgraph/drawiojgraph/drawio
CVE-2023-3974OS Command Injection in jgraph/drawiojgraph/drawio
CVE-2023-3973Cross-site Scripting (XSS) - Reflected in jgraph/drawiojgraph/drawio
CVE-2023-3398Denial of Service in jgraph/drawiojgraph/drawio
CVE-2023-3026Cross-site Scripting (XSS) - Stored in jgraph/drawiojgraph/drawio
CVE-2022-3873Cross-site Scripting (XSS) - DOM in jgraph/drawiojgraph/drawio
CVE-2022-3223Cross-site Scripting (XSS) - Stored in jgraph/drawiojgraph/drawio
CVE-2022-3148Cross-site Scripting (XSS) - Generic in jgraph/drawiojgraph/drawio
CVE-2022-3138Cross-site Scripting (XSS) - Generic in jgraph/drawiojgraph/drawio
CVE-2022-3133OS Command Injection in jgraph/drawiojgraph/drawio
CVE-2022-3127Cross-site Scripting (XSS) - Stored in jgraph/drawiojgraph/drawio
CVE-2022-3065Improper Access Control in jgraph/drawiojgraph/drawio
CVE-2022-2015Cross-site Scripting (XSS) - Stored in jgraph/drawiojgraph/drawio
CVE-2022-2014Code Injection in jgraph/drawiojgraph/drawio
CVE-2022-1815Exposure of Sensitive Information to an Unauthorized Actor in jgraph/drawiojgraph/drawio
CVE-2022-1784Server-Side Request Forgery (SSRF) in jgraph/drawiojgraph/drawio
CVE-2022-1774Exposure of Sensitive Information to an Unauthorized Actor in jgraph/drawiojgraph/drawio
CVE-2022-1767Server-Side Request Forgery (SSRF) in jgraph/drawiojgraph/drawio
CVE-2022-1730Cross-site Scripting (XSS) - Stored in jgraph/drawiojgraph/drawio
CVE-2022-1727Improper Input Validation in jgraph/drawiojgraph/drawio
CVE-2022-1723Server-Side Request Forgery (SSRF) in jgraph/drawiojgraph/drawio
CVE-2022-1722SSRF in editor's proxy via IPv6 link-local address in jgraph/drawiojgraph/drawio
CVE-2022-1721Path Traversal in WellKnownServlet in jgraph/drawiojgraph/drawio
CVE-2022-1713SSRF on /proxy in jgraph/drawiojgraph/drawio
CVE-2022-1711Server-Side Request Forgery (SSRF) in jgraph/drawiojgraph/drawio
CVE-2022-1575Arbitrary Code Execution through Sanitizer Bypass in jgraph/drawiojgraph/drawio

26 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.