CVE-2020-28500
πΆ mediumSummary
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
CVSS Score
5.3
Medium
EPSS Score
0.3
Exploit Probability
Published Date
2021-02-15
First Seen: 2026-01-05
π Relative Risk Intelligence
This CVE is Lower Risk - more severe than 19.8% of all 317,883 vulnerabilities in our database.
#254,789
Below average severity
Severity Percentile
Last Modified
2024-11-21
Source
NVD π
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L