Vulnerabilities > Jgraph > Mxgraph > 1.14.0.2

DATE CVE VULNERABILITY TITLE RISK
2019-07-01 CVE-2019-13127 Cross-site Scripting vulnerability in multiple products
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products.
network
draw jgraph CWE-79
4.3
2018-02-24 CVE-2017-18197 XXE vulnerability in Jgraph Mxgraph
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.
network
low complexity
jgraph CWE-611
7.5