CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-55810

Critical · CVSS 9.8

Drupal Plotly.js Graphing (drupal/plotly_js) — Improperly Controlled Modification of Dynamically-Determined Object Attributes (Object Injection)

CVSS
9.8
nvd
EPSS
0.16%
6th pct
KEV
No
Class
oss containerizable
CWE-915

Description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2.

Search profile — drives PoC discovery

Symbols plotly_jsdrupal/plotly_jsPlotlyJsplotly_js_graphingObject InjectionCWE-915sa-contrib-2026-050packages.drupal.org/8
Keywords CVE-2026-55810Drupal Plotly.jsplotly_js Object InjectionDrupal CWE-915Drupal sa-contrib-2026-050drupal/plotly_js exploitPlotly.js Graphing module vulnerabilityDrupal object injection PoC
Versions: 0.0.0 to 3.0.2

Affected packages

Packagist:https://packages.drupal.org/8 drupal/plotly_js 0 → 3.0.2

References

Status: enriched · ingested 2026-07-13T18:00:21.000Z · profiled 2026-07-13T18:30:21.000Z