Dojo
18 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Dojo, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Dojo CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 2 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 1 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 18 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High5
- Medium8
Latest CVEs
The 15 most recently published vulnerabilities affecting Dojo.
- CVE-2026-25117pwn.college DOJO vulnerable to sandbox escape leading to arbitrary javascript execution—
- CVE-2025-62376pwn.college DOJO vulnerable to improper authentication in workspace endpoint allowing unauthorized Windows VM access—
- CVE-2025-24885pwn.college has a XSS on dojo pages7.6
- CVE-2025-24886pwn.college has Symlink LFI in Dojo repos7.7
- CVE-2021-23450Prototype Pollution7.5
- CVE-2020-5258Prototype pollution in dojo7.7
- CVE-2020-5259Prototype Pollution in Dojox7.7
- CVE-2018-1000665Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and te...6.1
- CVE-2018-15494In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.9.8
- CVE-2018-6561dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element.6.1
- CVE-2015-5654Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.4.3
- CVE-2010-2273Multiple cross-site scripting (XSS) vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to inject a...4.3
- CVE-2010-2272Unspecified vulnerability in iframe_history.html in Dojo 0.4.x before 0.4.4 has unknown impact and remote attack vectors.10.0
- CVE-2010-2274Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arb...4.3
- CVE-2010-2275Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the theme parameter, as de...4.3
Product grouping is registry-driven, with AI assist and human review. How it works