mpxj
PyPI4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting mpxjpage 1 of 1
- CVE-2022-41954LOWCVSS 3.3EG 3.3fixed in 10.14.12022-11-25
vulnerable: 10.0.0 ... 9.8.3 (44 versions)
MPXJ is an open source library to read and write project plans from a variety of file formats and databases. On Unix-like operating systems (not Windows or macos), MPXJ's use of `File.createTempFile(..)` results in temporary files being cr…
- CVE-2024-49771MEDIUMCVSS 5.3EG 5.3fixed in 13.5.12024-10-28
vulnerable: 10.0.0 ... 9.8.3 (95 versions)
MPXJ is an open source library to read and write project plans from a variety of file formats and databases. The patch for the historical vulnerability CVE-2020-35460 in MPXJ is incomplete as there is still a possibility that a malicious p…
- CVE-2026-61570HIGHCVSS 7.5EG 7.5fixed in 16.4.12026-09-22
vulnerable: 10.0.0 ... 9.8.3 (126 versions)
MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 5.5.5 until 16.4.1, MerlinReader creates a DocumentBuilder with default settings while parsing XML from the ZTIMEINTERVALS co…
- CVE-2026-65829MEDIUMCVSS 5.3EG 5.3fixed in 16.5.02026-09-22
vulnerable: 10.0.0 ... 9.8.3 (127 versions)
MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 until 16.5.0, reading a suitably crafted Primavera P3 PRX or SureTrak STX file can cause MPXJ to write files to arbitra…
Check whether mpxj is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for mpxj CVEs against the assets you own.
Book a Demo →