VendorsVega Projectvegaany version
Vulnerabilities

Vega Project Vega any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2025-65110
Vega Cross-Site Scripting (XSS) via expression abusing vlSelectionTuples function array map calls in environments with satisfactory function gadgets in the global scope
Published 2026-01-05 · Analyzed
9.3EPSS 0.005
CVE-2020-26296
XSS in Vega
Published 2020-12-30 · Modified
8.7EPSS 0.017
CVE-2023-26487
Vega has cross-site scripting vulnerability in `lassoAppend` function
Published 2023-03-03 · Modified
6.5EPSS 0.008
CVE-2023-26486
Vega `scale` expression function cross site scripting
Published 2023-03-03 · Modified
6.5EPSS 0.008
CVE-2025-26619
Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode `expressionInterpeter`
Published 2025-03-27 · Analyzed
6.1EPSS 0.003
CVE-2019-10806
vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype.
Published 2020-03-09 · Modified
4.3EPSS 0.011