Known Vulnerabilities for Cordova by Apache

Listed below are 10 of the newest known vulnerabilities associated with "Cordova" by "Apache".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2021-21315 json The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to ret... 7.8 - HIGH 2021-02-16 2023-11-07
CVE-2020-11990 json We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An at... 3.3 - LOW 2020-12-01 2022-01-01
CVE-2017-3160 json After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, the scr... 7.4 - HIGH 2018-02-01 2020-04-15
CVE-2016-6799 json Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these m... 7.5 - HIGH 2017-05-09 2023-11-07
CVE-2015-8320 json Apache Cordova-Android before 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for attac... 5 - MEDIUM 2015-11-23 2018-10-09
CVE-2015-5256 json Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript whitel... 4.3 - MEDIUM 2015-11-23 2018-10-09
CVE-2015-5208 json Apache Cordova iOS before 4.0.0 allows remote attackers to execute arbitrary plugins via a link. 4.4 - MEDIUM 2016-05-09 2018-10-09
CVE-2015-5207 json Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load arbit... 5.3 - MEDIUM 2016-05-09 2018-10-09
CVE-2015-1835 json Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, all... 5.3 - MEDIUM 2017-10-27 2017-11-16
CVE-2014-3502 json Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL with a ... 4.3 - MEDIUM 2014-11-15 2014-11-17

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationApacheCordova7.1.0
ApplicationApacheCordova7.0.0
ApplicationApacheCordova6.4.0
ApplicationApacheCordova6.3.0
ApplicationApacheCordova6.2.3
ApplicationApacheCordova6.2.2
ApplicationApacheCordova6.2.1
ApplicationApacheCordova6.2.0
ApplicationApacheCordova6.2.0
ApplicationApacheCordova6.1.2
ApplicationApacheCordova6.1.1
ApplicationApacheCordova6.1.1
ApplicationApacheCordova6.1.0
ApplicationApacheCordova6.1.0
ApplicationApacheCordova6.0.0
ApplicationApacheCordova6.0.0
ApplicationApacheCordova5.2.2
ApplicationApacheCordova5.2.1
ApplicationApacheCordova5.2.0
ApplicationApacheCordova5.1.1
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report