mpxj CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

mpxj vulnerability overview

Aggregates CVE and security vulnerability intelligence across all mpxj-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk path handling and vendor risk xxe; exposure may include vendor impact file overwrite in vendor surface software deployment and vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2022-41954 MPXJ is an open source library to read and write project plans from a variety of file formats and databases. On Unix-like operating systems (not Windows or macos), MPXJ's use of `File.createTempFile(..)` results in temporary files being created with the permissions `-rw-r--r--`. This means that any other user on the system can read the contents of this file. When MPXJ is reading a schedule file which requires the creation of a temporary file or directory, a knowledgeable local user could locate [email protected] 3.3 0.21% 2022-11-25 2024-11-21
CVE-2020-35460 common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations. [email protected] 5.3 1.76% 2020-12-14 2025-05-05
CVE-2020-25020 MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components. [email protected] 9.8 2.59% 2020-08-29 2025-05-05
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence