Pmd / Pmd
3 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-28338 | PMD Designer has Stored XSS in VBHTMLRenderer and YAHTMLRenderer via unescaped violation messages | MEDIUM | 6.8 | Feb 27, 2026 |
| CVE-2025-23215 | PMD Designer's release key passphrase (GPG) available on Maven Central in cleartext | CRITICAL | 9.3 | Jan 31, 2025 |
| CVE-2019-7722 | PMD 5.8.1 and earlier processes XML external entities in ruleset files it parses as part of the analysis process, allowing attackers tampering it (either by di… | HIGH | 8.1 | Feb 11, 2019 |
Showing 1 to 3 of 3 CVEs