Cordova
This hub aggregates every CVE we track for Cordova, a product in the mobile apps space. Use it to gauge the current risk picture and drill into individual advisories.
19
CVEs tracked
2
Critical
8
High
1
In CISA KEV
Severity distribution
HIGH8MEDIUM8CRITICAL2LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Cordova.
- CVE-2021-21315Command Injection VulnerabilityKEV7.1
- CVE-2020-11990We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially cra...3.3
- CVE-2019-0219A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.9.8
- CVE-2017-3160After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, the scripts will fetch Gradle on the first build. However, since the default UR...7.4
- CVE-2014-0072ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0.4.2 for iOS and the File-Transfer plugin for iOS from Cordova 2.4.0 through 2...7.5
- CVE-2014-0073The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 thro...9.8
- CVE-2015-1835Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to modify undefined secondary configuration variabl...5.3
- CVE-2016-6799Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()) are stored in a...7.5
- CVE-2015-5207Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by leveraging unspecified methods.5.3
- CVE-2015-5208Apache Cordova iOS before 4.0.0 allows remote attackers to execute arbitrary plugins via a link.4.4
- CVE-2015-8320Apache Cordova-Android before 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for attackers to conduct bridge hijacking attacks by predicting a value.5.0
- CVE-2015-5256Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript whitelist protection mechanism, which allows attackers to bypass intended acce...4.3
- CVE-2014-3502Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent.4.3
- CVE-2014-3500Apache Cordova Android before 3.5.1 allows remote attackers to change the start page via a crafted intent URL.6.4
- CVE-2014-3501Apache Cordova Android before 3.5.1 allows remote attackers to bypass the HTTP whitelist and connect to arbitrary servers by using JavaScript to open WebSocket connections through WebView.4.3
Product normalization is registry-driven with AI assist and human review. How it works