Vulnerabilities > Plotly

DATE CVE VULNERABILITY TITLE RISK
2024-02-02 CVE-2024-21485 Cross-site Scripting vulnerability in Plotly Dash
Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the package dash before 2.15.0; versions of the package dash-html-components before 2.0.0; versions of the package dash-html-components before 2.0.16 are vulnerable to Cross-site Scripting (XSS) when the href of the a tag is controlled by an adversary.
network
low complexity
plotly CWE-79
5.4
2024-01-03 CVE-2023-46308 Unspecified vulnerability in Plotly Plotly.Js
In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.
network
low complexity
plotly
critical
9.8
2017-07-17 CVE-2017-1000006 Cross-site Scripting vulnerability in Plotly Plotly.Js
Plotly, Inc.
network
plotly CWE-79
4.3