CVE-2017-1000006: Plotly Plotly.js

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

Plotly, Inc. plotly.js versions prior to 1.16.0 are vulnerable to an XSS issue.

Affected products

  • Plotly Plotly.js: version 1.11.0 only; version 1.12.0 only; version 1.13.0 only; version 1.14.0 only; version 1.14.1 only; version 1.14.2 only; …

Published 2017-07-17. Last modified 2026-06-17.