matrix-react-sdk
matrix-org- Product type
- Other
- Catalog vulnerabilities
- 8
Severity across 8 analyzed records
Verify to analyze this security profile
en
Severity across 8 analyzed records
Verify to analyze this security profile
As of 09/14/2026, within CyStack's analyzed data, matrix-react-sdk has 0 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of matrix-react-sdk and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2024-47824Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a room | Exploitation statusNot known exploited | FixNot confirmed | Published10/15/2024 | SeverityHigh |
CVE-2024-42347URL preview setting for a room is controllable by the homeserver in matrix-react-sdk | Exploitation statusNot known exploited | FixYes | Published08/06/2024 | SeverityHigh |
CVE-2023-37259Cross site scripting in Export Chat feature | Exploitation statusNot known exploited | FixNot confirmed | Published07/18/2023 | SeverityMedium |
CVE-2023-30609matrix-react-sdk vulnerable to HTML injection in search results via plaintext message highlighting | Exploitation statusNot known exploited | FixNot confirmed | Published04/25/2023 | SeverityMedium |
CVE-2022-36060Prototype pollution in matrix-react-sdk | Exploitation statusNot known exploited | FixYes | Published03/28/2023 | SeverityHigh |
CVE-2023-28103Prototype pollution in matrix-react-sdk | Exploitation statusNot known exploited | FixYes | Published03/28/2023 | SeverityHigh |
CVE-2021-32622File upload local preview can run embedded scripts after user interaction | Exploitation statusNot confirmed | FixYes | Published05/17/2021 | SeverityMedium |
CVE-2021-21320User content sandbox can be confused into opening arbitrary documents | Exploitation statusNot confirmed | FixYes | Published03/02/2021 | SeverityLow |