Where
-Infinity
0

Vendor Risk Score

See how diagrams compares to other vendors in security performance

View Risk Score →

jgraph draw.iodraw.io: XSS via crafted cell label when opening a .drawio file

Risk 38
Severity
6.1
First published (updated )

Diagrams DrawioOS Command Injection in jgraph/drawio

Risk 86
Severity
9.8
First published (updated )

Diagrams DrawioOS Command Injection in jgraph/drawio

Risk 86
Severity
9.8
First published (updated )

Diagrams DrawioCross-site Scripting (XSS) - Reflected in jgraph/drawio

Risk 76
Severity
9.6
First published (updated )

Diagrams DrawioDenial of Service in jgraph/drawio

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Diagrams DrawioCross-site Scripting (XSS) - Stored in jgraph/drawio

Risk 40
Severity
6.5
First published (updated )

Diagrams DrawioCross-site Scripting (XSS) - DOM in jgraph/drawio

Risk 40
Severity
6.5
First published (updated )

Diagrams DrawioCross-site Scripting (XSS) - Stored in jgraph/drawio

Risk 38
Severity
6.1
First published (updated )

Diagrams DrawioOS Command Injection in jgraph/drawio

Risk 68
Severity
7.8
First published (updated )

Diagrams DrawioCross-site Scripting (XSS) - Generic in jgraph/drawio

Risk 38
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Diagrams DrawioCross-site Scripting (XSS) - Generic in jgraph/drawio

Risk 38
Severity
6.1
First published (updated )

Diagrams DrawioCross-site Scripting (XSS) - Stored in jgraph/drawio

Risk 31
Severity
5.5
First published (updated )

Diagrams DrawioImproper Access Control in jgraph/drawio

Risk 43
Severity
7.5
First published (updated )

Diagrams DrawioCross-site Scripting (XSS) - Stored in jgraph/drawio

Risk 38
Severity
6.1
First published (updated )

Diagrams DrawioCode Injection in jgraph/drawio

Risk 76
Severity
9.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Diagrams DrawioExposure of Sensitive Information to an Unauthorized Actor in jgraph/drawio

Risk 43
Severity
7.5
First published (updated )

Diagrams DrawioServer-Side Request Forgery (SSRF) in jgraph/drawio

Risk 43
Severity
7.5
First published (updated )

Diagrams DrawioCross-site Scripting (XSS) - Stored in jgraph/drawio

Risk 45
Severity
6.3
First published (updated )

Diagrams DrawioExposure of Sensitive Information to an Unauthorized Actor in jgraph/drawio

Risk 53
Severity
8.2
First published (updated )

Diagrams DrawioServer-Side Request Forgery (SSRF) in jgraph/drawio

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Diagrams DrawioImproper Input Validation in jgraph/drawio

Risk 77
Severity
8.8
First published (updated )

Diagrams DrawioServer-Side Request Forgery (SSRF) in jgraph/drawio

Risk 43
Severity
7.5
First published (updated )

Diagrams DrawioServer-Side Request Forgery (SSRF) in jgraph/drawio

Risk 43
Severity
7.5
First published (updated )

Diagrams DrawioSSRF on /proxy in jgraph/drawio

Risk 43
Severity
7.5
First published (updated )

Diagrams DrawioPath Traversal in WellKnownServlet in jgraph/drawio

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Diagrams DrawioSSRF in editor's proxy via IPv6 link-local address in jgraph/drawio

Risk 51
Severity
7.5
First published (updated )

Diagrams DrawioArbitrary Code Execution through Sanitizer Bypass in jgraph/drawio

Risk 76
Severity
9.6
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203