Known Vulnerabilities for Diagram by DHTMLX
Listed below are 10 of the newest known vulnerabilities associated with "Diagram" by "DHTMLX".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-59791 json | In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-49492 json | Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does not validate... | Not Provided | 2026-06-05 | 2026-06-05 |
| CVE-2026-43194 json | In the Linux kernel, the following vulnerability has been resolved: net: consume xmit errors of GSO frames udpgro_frglist.s... | Not Provided | 2026-05-06 | 2026-05-08 |
| CVE-2026-42140 json | PlantUML Macro is a macro for rendering UML diagrams from simple textual schemes. Prior to version 2.4.1, the PlantUML Macro ... | Not Provided | 2026-05-04 | 2026-05-04 |
| CVE-2026-41159 json | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 1... | Not Provided | 2026-05-29 | 2026-07-01 |
| CVE-2026-41150 json | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 1... | Not Provided | 2026-05-29 | 2026-05-29 |
| CVE-2026-41149 json | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and e... | Not Provided | 2026-05-22 | 2026-05-23 |
| CVE-2026-41148 json | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and p... | Not Provided | 2026-05-22 | 2026-05-22 |
| CVE-2026-31981 json | A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation funct... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2026-7182 json | Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization. An unauthenticate... | Not Provided | 2026-05-15 | 2026-05-15 |