CVE-2019-13127: Draw Draw.io Diagrams
Medium severity, CVSS 6.1. EPSS: 1.5% chance of exploitation in the next 30 days.
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs.js.
Affected products
Published 2019-07-01. Last modified 2026-06-17.