Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

jgraph — Vulnerabilities & Security Advisories 33

Browse all 33 CVE security advisories affecting jgraph. AI-powered Chinese analysis, POCs, and references for each vulnerability.

JGraph is a software development toolkit primarily utilized for creating interactive diagrams and flowcharts within Java-based applications. Its widespread adoption in enterprise environments has made it a frequent target for security researchers, resulting in twenty-six recorded Common Vulnerabilities and Exposures (CVEs). Historically, the most prevalent vulnerability classes affecting this library include Remote Code Execution (RCE) and Cross-Site Scripting (XSS), often stemming from insufficient input validation in XML parsing routines. These flaws typically allow attackers to execute arbitrary commands or inject malicious scripts when processing untrusted diagram files. While no single catastrophic incident has defined its security history, the cumulative impact of these CVEs highlights significant risks in legacy versions. Organizations relying on JGraph must prioritize regular updates to mitigate exposure to these well-documented exploitation vectors, ensuring that diagram processing components remain patched against known injection techniques.

Top products by jgraph: jgraph/drawio drawio
CVE ID Title CVSS Severity Published
CVE-2026-76898 draw.io: Unauthenticated SSRF via IPv6 ULA blocklist bypass in /embed2.js — drawio CWE-918 7.7 High 2026-09-21
CVE-2026-63373 draw.io: OAuth CSRF via missing state validation on self-hosted deployments allows session token injection — drawio CWE-352 4.2 Medium 2026-09-21
CVE-2026-63334 draw.io: SSRF via DNS rebinding in ProxyServlet bypasses private IP blocklist — drawio CWE-918 6.8 Medium 2026-09-21
CVE-2026-63416 draw.io: Path traversal in ExportProxyServlet allows access to arbitrary backend endpoints — drawio CWE-22 3.7 Low 2026-09-21
CVE-2026-58504 draw.io: Stored XSS on file open via editable=0 sibling cell — patch bypass of CVE-2026-46642 — drawio CWE-79 6.1 Medium 2026-09-21
CVE-2026-46642 draw.io: XSS via crafted cell label when opening a .drawio file — drawio CWE-79 6.1 Medium 2026-06-10
CVE-2026-42195 Unvalidated gitlab URL parameter redirects OAuth authorize step to attacker-controlled host — drawio CWE-601 3.4 Low 2026-05-08
CVE-2023-3975 OS Command Injection in jgraph/drawio — jgraph/drawio CWE-78 8.8 - 2023-07-27
CVE-2023-3974 OS Command Injection in jgraph/drawio — jgraph/drawio CWE-78 8.8 - 2023-07-27
CVE-2023-3973 Cross-site Scripting (XSS) - Reflected in jgraph/drawio — jgraph/drawio CWE-79 6.1 - 2023-07-27
CVE-2023-3398 Denial of Service in jgraph/drawio — jgraph/drawio CWE-400 6.5 - 2023-06-26
CVE-2023-3026 Cross-site Scripting (XSS) - Stored in jgraph/drawio — jgraph/drawio CWE-79 5.4 - 2023-06-01
CVE-2022-3873 Cross-site Scripting (XSS) - DOM in jgraph/drawio — jgraph/drawio CWE-79 6.1 - 2022-11-07
CVE-2022-3223 Cross-site Scripting (XSS) - Stored in jgraph/drawio — jgraph/drawio CWE-79 5.4 - 2022-09-16
CVE-2022-3133 OS Command Injection in jgraph/drawio — jgraph/drawio CWE-78 8.8 - 2022-09-09
CVE-2022-3138 Cross-site Scripting (XSS) - Generic in jgraph/drawio — jgraph/drawio CWE-79 6.1 - 2022-09-08
CVE-2022-3148 Cross-site Scripting (XSS) - Generic in jgraph/drawio — jgraph/drawio CWE-79 6.1 - 2022-09-08
CVE-2022-3127 Cross-site Scripting (XSS) - Stored in jgraph/drawio — jgraph/drawio CWE-79 5.4 - 2022-09-05
CVE-2022-3065 Improper Access Control in jgraph/drawio — jgraph/drawio CWE-284 5.7 - 2022-09-02
CVE-2022-2015 Cross-site Scripting (XSS) - Stored in jgraph/drawio — jgraph/drawio CWE-79 5.4 - 2022-06-08
CVE-2022-2014 Code Injection in jgraph/drawio — jgraph/drawio CWE-94 6.1 - 2022-06-08
CVE-2022-1815 Exposure of Sensitive Information to an Unauthorized Actor in jgraph/drawio — jgraph/drawio CWE-200 6.5 - 2022-05-25
CVE-2022-1784 Server-Side Request Forgery (SSRF) in jgraph/drawio — jgraph/drawio CWE-918 7.5 - 2022-05-20
CVE-2022-1730 Cross-site Scripting (XSS) - Stored in jgraph/drawio — jgraph/drawio CWE-79 5.4 - 2022-05-19
CVE-2022-1774 Exposure of Sensitive Information to an Unauthorized Actor in jgraph/drawio — jgraph/drawio CWE-200 6.5 - 2022-05-18
CVE-2022-1767 Server-Side Request Forgery (SSRF) in jgraph/drawio — jgraph/drawio CWE-918 7.5 - 2022-05-18
CVE-2022-1727 Improper Input Validation in jgraph/drawio — jgraph/drawio CWE-20 8.8 - 2022-05-18
CVE-2022-1711 Server-Side Request Forgery (SSRF) in jgraph/drawio — jgraph/drawio CWE-918 7.5 - 2022-05-17
CVE-2022-1723 Server-Side Request Forgery (SSRF) in jgraph/drawio — jgraph/drawio CWE-918 7.5 - 2022-05-17
CVE-2022-1713 SSRF on /proxy in jgraph/drawio — jgraph/drawio CWE-918 7.5 - 2022-05-16

This page lists every published CVE security advisory associated with jgraph. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.