wpewebkit CVE Vulnerabilities & Metrics

Focus on wpewebkit vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About wpewebkit Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with wpewebkit. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total wpewebkit CVEs: 19
Earliest CVE date: 19 Jun 2018, 21:29 UTC
Latest CVE date: 14 May 2024, 15:13 UTC

Latest CVE reference: CVE-2024-27834

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -87.5%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -87.5%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical wpewebkit CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.32

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 12
4.0-6.9 5
7.0-8.9 2
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS wpewebkit CVEs

These are the five CVEs with the highest CVSS scores for wpewebkit, sorted by severity first and recency.

All CVEs for wpewebkit

CVE-2024-27834 wpewebkit vulnerability CVSS: 0 14 May 2024, 15:13 UTC

The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, Safari 17.5, watchOS 10.5, macOS Sonoma 14.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.

CVE-2024-23284 wpewebkit vulnerability CVSS: 0 08 Mar 2024, 02:15 UTC

A logic issue was addressed with improved state management. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, iOS 16.7.6 and iPadOS 16.7.6, Safari 17.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

CVE-2024-23280 wpewebkit vulnerability CVSS: 0 08 Mar 2024, 02:15 UTC

An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4, tvOS 17.4. A maliciously crafted webpage may be able to fingerprint the user.

CVE-2024-23263 wpewebkit vulnerability CVSS: 0 08 Mar 2024, 02:15 UTC

A logic issue was addressed with improved validation. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, iOS 16.7.6 and iPadOS 16.7.6, Safari 17.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

CVE-2024-23254 wpewebkit vulnerability CVSS: 0 08 Mar 2024, 02:15 UTC

The issue was addressed with improved UI handling. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, Safari 17.4. A malicious website may exfiltrate audio data cross-origin.

CVE-2023-42843 wpewebkit vulnerability CVSS: 0 21 Feb 2024, 07:15 UTC

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.

CVE-2023-40397 wpewebkit vulnerability CVSS: 0 06 Sep 2023, 21:15 UTC

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. A remote attacker may be able to cause arbitrary javascript code execution.

CVE-2023-32370 wpewebkit vulnerability CVSS: 0 06 Sep 2023, 02:15 UTC

A logic issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3. Content Security Policy to block domains with wildcards may fail.

CVE-2023-28198 wpewebkit vulnerability CVSS: 0 14 Aug 2023, 23:15 UTC

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. Processing web content may lead to arbitrary code execution.

CVE-2019-8720 wpewebkit vulnerability CVSS: 0 06 Mar 2023, 23:15 UTC

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.

CVE-2022-32893 wpewebkit vulnerability CVSS: 0 24 Aug 2022, 20:15 UTC

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVE-2022-2294 wpewebkit vulnerability CVSS: 0 28 Jul 2022, 02:15 UTC

Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-42762 wpewebkit vulnerability CVSS: 4.6 20 Oct 2021, 19:15 UTC

BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined. NOTE: this is similar to CVE-2021-41133.

CVE-2020-13753 wpewebkit vulnerability CVSS: 7.5 14 Jul 2020, 14:15 UTC

The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the sandbox by writing to the controlling terminal's input buffer, similar to CVE-2017-5226.

CVE-2020-11793 wpewebkit vulnerability CVSS: 6.8 17 Apr 2020, 13:15 UTC

A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash).

CVE-2020-10018 wpewebkit vulnerability CVSS: 7.5 02 Mar 2020, 23:15 UTC

WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution. This issue has been fixed in 2.28.0 with improved memory handling.

CVE-2019-11070 wpewebkit vulnerability CVSS: 5.0 10 Apr 2019, 21:29 UTC

WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.

CVE-2019-6251 wpewebkit vulnerability CVSS: 5.8 14 Jan 2019, 08:29 UTC

WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.

CVE-2018-12293 wpewebkit vulnerability CVSS: 6.8 19 Jun 2018, 21:29 UTC

The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer overflow, which could be abused by crafted HTML content.