net.sourceforge.plantuml
cpe:2.3:a:plantuml:plantuml:*:*:*:*:*:*:*
- < 1.2026.0
A stored cross-site scripting vulnerability has been identified in PlantUML versions prior to 1.2026.0. This issue arises from inadequate sanitization of interactive attributes within GraphViz diagrams. Consequently, a maliciously crafted PlantUML diagram can embed harmful JavaScript into the resulting SVG output. When this SVG is rendered by applications, it can execute arbitrary scripts, potentially leading to security breaches.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the SVG.
Users can upgrade to PlantUML version 1.2026.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.