CVE-2017-18197: Jgraph Mxgraph
Critical severity, CVSS 9.8. EPSS: 2.9% chance of exploitation in the next 30 days.
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.
Affected products
- Jgraph Mxgraph: up to and including 3.7.5
Published 2018-02-24. Last modified 2026-06-17.