Known vulnerabilities in Eclipse Theia
Vendor:
Eclipse
Software:
Eclipse Theia
Software CPE:
cpe:2.3:a:eclipse:eclipse_theia:*:*:*:*:*:*:*:*
Website:
https://eclipse.org
Total vulnerabilities:
6
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
1.74.0
1.73.1
1.73.0
1.72.3
1.72.2
1.72.1
1.72.0
1.71.2
1.71.1
1.71.0
1.70.2
1.70.1
1.70.0
1.69.0
1.68.2
1.68.1
1.68.0
1.67.0
1.66.2
1.66.1
1.66.0
1.65.2
1.64.4
1.64.3
1.65.1
1.64.2
1.65.0
1.64.1
1.64.0
1.63.3
1.63.2
1.63.1
1.63.0
1.62.2
1.61.1
1.62.1
1.62.0
1.61.0
1.60.2
1.58.5
1.60.1
1.60.0
1.58.4
1.59.0
1.58.3
1.58.1
1.58.0
1.57.1
1.57.0
1.55.1
1.56.0
1.55.0
1.54.0
1.53.2
1.53.1
1.53.0
1.52.0
1.51.0
1.46.101
1.50.1
1.50.0
1.49.1
1.49.0
1.48.3
1.48.2
1.48.0
1.47.1
1.47.0
1.46.1
1.46.0
1.45.1
1.45.0
1.44.0
1.43.1
1.43.0
1.42.1
1.42.0
1.41.0
1.40.1
1.40.0
1.39.0
1.37.2
1.38.0
1.37.1
1.37.0
1.36.0
1.34.4
1.34.3
1.34.2
1.35.0
1.34.0
1.33.0
1.32.0
1.31.1
1.31.0
1.30.0
1.29.0
1.28.0
1.27.0
1.26.0
1.25.0
1.24.0
1.23.0
1.22.1
1.22.0
1.21.0
1.20.0
1.19.0
1.18.0
1.17.2
1.17.1
1.17.0
1.16.0
1.15.0
1.14.0
1.13.0
1.12.1
1.12.0
1.11.0
1.10.0
1.9.0
1.8.1
1.8.0
1.7.0
1.6.0
1.5.0
1.4.0
1.3.0
1.2.0
1.1.0
1.0.0
0.16.1
0.16.0
0.15.0
0.14.0
0.13.0
0.12.0
0.11.0
0.10.0
0.9.0
0.8.0
0.7.2
0.7.1
0.7.0
0.6.1
0.6.0
0.5.0
0.4.0
0.3.19
0.3.18
0.3.17
0.3.16
0.3.15
0.3.14
0.3.13
0.3.12
0.3.11
0.3.10
0.3.9
0.3.8
0.3.7
0.3.6
0.3.4
0.3.3
0.3.2
0.3.1
0.3.0
0.2.4
0.2.3
0.2.2
0.2.1
0.2.0
0.1.1
0.1.0
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU139169 - Missing Origin Validation in WebSockets CVE-2026-10054 |
CWE-1385 | High | 1.73.0 | 22.07.2026 |
SB2026072287 |
||
| #VU139168 - Server-Side Request Forgery (SSRF) CVE-2026-10055 |
CWE-918 | Medium | 1.73.0 | 22.07.2026 |
SB2026072287 |
||
| #VU56302 - Improper Control of Generation of Code ('Code Injection') CVE-2021-34435 |
CWE-94 | High | 1.9.0 | 03.09.2021 |
SB2021090313 |
||
| #VU51609 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2021-28162 |
CWE-79 | Low | 0.16.1 | 22.03.2021 |
SB2021032219 |
||
| #VU51608 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2021-28161 |
CWE-79 | Low | 1.8.1 | 22.03.2021 |
SB2021032218 |
||
| #VU26096 - Insufficient Verification of Data Authenticity CVE-2019-17636 |
CWE-345 | High | 0.16.0 | 16.03.2020 |
SB2020031606 |