Cordova
This hub aggregates every CVE we track for Cordova, a product in the mobile apps space. Use it to gauge the current risk picture and drill into individual advisories.
19
CVEs tracked
2
Critical
8
High
1
In CISA KEV
Severity distribution
HIGH8MEDIUM8CRITICAL2LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Cordova.
- CVE-2021-21315Command Injection VulnerabilityKEV7.1
- CVE-2020-11990We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially cra...3.3
- CVE-2019-0219A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.9.8
- CVE-2017-3160After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, the scripts will fetch Gradle on the first build. However, since the default UR...7.4
- CVE-2014-0072ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0.4.2 for iOS and the File-Transfer plugin for iOS from Cordova 2.4.0 through 2...7.5
- CVE-2014-0073The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 thro...9.8
- CVE-2015-1835Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to modify undefined secondary configuration variabl...5.3
- CVE-2016-6799Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()) are stored in a...7.5
- CVE-2015-5207Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by leveraging unspecified methods.5.3
- CVE-2015-5208Apache Cordova iOS before 4.0.0 allows remote attackers to execute arbitrary plugins via a link.4.4
- CVE-2015-8320Apache Cordova-Android before 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for attackers to conduct bridge hijacking attacks by predicting a value.5.0
- CVE-2015-5256Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript whitelist protection mechanism, which allows attackers to bypass intended acce...4.3
- CVE-2014-3501Apache Cordova Android before 3.5.1 allows remote attackers to bypass the HTTP whitelist and connect to arbitrary servers by using JavaScript to open WebSocket connections through WebView.4.3
- CVE-2014-3502Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent.4.3
- CVE-2014-3500Apache Cordova Android before 3.5.1 allows remote attackers to change the start page via a crafted intent URL.6.4
Product normalization is registry-driven with AI assist and human review. How it works