📦 Drawio

by Diagrams

🔍 What is Drawio?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-1575

CRITICAL CVSS 9.6 May 5, 2022

CVE-2022-1575 is a critical vulnerability in draw.io diagramming software that allows attackers to bypass input sanitization and execute arbitrary code. In the desktop application, this leads to remot...

CVE-2023-3398

HIGH CVSS 7.5 Jun 26, 2023

This CVE describes a Denial of Service vulnerability in the draw.io diagramming software. Attackers can cause the application to crash or become unresponsive by exploiting resource exhaustion. All use...

CVE-2022-1815

HIGH CVSS 7.5 May 25, 2022

CVE-2022-1815 is an information disclosure vulnerability in draw.io diagramming software that exposes sensitive information to unauthorized actors. The vulnerability allows attackers to access sensiti...

CVE-2022-1767

HIGH CVSS 7.5 May 18, 2022

This Server-Side Request Forgery (SSRF) vulnerability in draw.io allows attackers to make unauthorized requests from the server to internal systems. It affects users running draw.io versions prior to ...

CVE-2022-1727

HIGH CVSS 8.8 May 18, 2022

CVE-2022-1727 is an improper input validation vulnerability in draw.io diagramming software that allows attackers to execute arbitrary code by tricking users into opening malicious diagram files. This...

CVE-2022-1711

HIGH CVSS 7.5 May 17, 2022

This Server-Side Request Forgery (SSRF) vulnerability in draw.io allows attackers to make unauthorized requests from the server to internal systems. It affects users of draw.io versions prior to 18.0....

CVE-2022-1713

HIGH CVSS 7.5 May 16, 2022

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the /proxy endpoint of draw.io diagramming software. Attackers can exploit this to make requests from the server's perspective,...