Parall / Jspdf
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-31938 | jsPDF has HTML Injection in New Window paths | CRITICAL | 9.6 | Mar 18, 2026 |
| CVE-2026-31898 | jsPDF has a PDF Object Injection via FreeText color | HIGH | 8.1 | Mar 18, 2026 |
| CVE-2026-25940 | jsPDF's PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property) | CRITICAL | 9.6 | Feb 19, 2026 |
| CVE-2026-25755 | jsPDF has PDF Object Injection via Unsanitized Input in addJS Method | CRITICAL | 9.6 | Feb 19, 2026 |
| CVE-2026-25535 | jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions | HIGH | 8.7 | Feb 19, 2026 |
| CVE-2026-24040 | jsPDF has a Shared State Race Condition in addJS Plugin | MEDIUM | 6.3 | Feb 2, 2026 |
| CVE-2026-24043 | jsPDF Affected by Stored XMP Metadata Injection (Spoofing & Integrity Violation) | MEDIUM | 6.9 | Feb 2, 2026 |
| CVE-2026-24133 | jsPDF Affected by Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder | HIGH | 8.7 | Feb 2, 2026 |
| CVE-2026-24737 | jsPDF has a PDF Injection in AcroFormChoiceField which allows Arbitrary JavaScript Execution | HIGH | 8.3 | Feb 2, 2026 |
| CVE-2025-68428 | jsPDF has Local File Inclusion/Path Traversal vulnerability | CRITICAL | 9.2 | Jan 5, 2026 |
| CVE-2025-57810 | jsPDF Parsing of Corrupt PNGs Leads to Potential Denial of Service (DoS) | HIGH | 8.7 | Aug 26, 2025 |
| CVE-2025-29907 | jsPDF Bypass Regular Expression Denial of Service (ReDoS) | HIGH | 8.7 | Mar 18, 2025 |
| CVE-2021-23353 | Regular Expression Denial of Service (ReDoS) | HIGH | 7.5 | Mar 9, 2021 |
| CVE-2020-7690 | All affected versions <2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS). It is possible to inject JavaScript code via the html method. | MEDIUM | 6.1 | Jul 6, 2020 |
| CVE-2020-7691 | Cross-site Scripting (XSS) | MEDIUM | 6.3 | Jul 6, 2020 |
Showing 1 to 15 of 15 CVEs