Vulnerabilities > Vega Project

DATE CVE VULNERABILITY TITLE RISK
2023-03-04 CVE-2023-26486 Cross-site Scripting vulnerability in multiple products
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs.
network
low complexity
vega-functions-project vega-project CWE-79
6.1
2023-03-04 CVE-2023-26487 Cross-site Scripting vulnerability in multiple products
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs.`lassoAppend' function accepts 3 arguments and internally invokes `push` function on the 1st argument specifying array consisting of 2nd and 3rd arguments as `push` call argument.
network
low complexity
vega-functions-project vega-project CWE-79
6.1
2020-12-30 CVE-2020-26296 Cross-site Scripting vulnerability in Vega Project Vega
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs.
3.5
2020-03-09 CVE-2019-10806 Unspecified vulnerability in Vega Project Vega
vega-util prior to 1.13.1 allows manipulation of object prototype.
network
low complexity
vega-project
4.3