Known vulnerabilities in JSONPath
Vendor:
JSONPath-Plus
Software:
JSONPath
Software CPE:
cpe:2.3:a:jsonpath-plus:jsonpath:*:*:*:*:*:*:*:*
Website:
https://github.com/JSONPath-Plus
Total vulnerabilities:
2
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU107638 - Improper Control of Generation of Code ('Code Injection') CVE-2025-1302 |
CWE-94 | Critical | 10.3.0 | 22.04.2025 |
SB2025042218 SB2025042219 SB2025050906 and 8 more |
||
| #VU100117 - Improper input validation CVE-2024-21534 |
CWE-20 | High | 10.0.7 | 08.11.2024 |
SB2024110840 SB2024110841 SB2024111516 and 17 more |