VYPR

Canva

by Canva

CVEs (4)

  • CVE-2026-85085CriSep 4, 2026
    risk 0.62cvss 9.6epss 0.00

    The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.

  • CVE-2026-85094HigSep 4, 2026
    risk 0.57cvss 8.8epss 0.00

    The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.

  • CVE-2026-92839MedSep 17, 2026
    risk 0.28cvss 4.3epss 0.00

    Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.

  • CVE-2025-12792LowNov 18, 2025
    risk 0.21cvss 3.2epss 0.00

    The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unprivileged access could execute arbitrary code that inherits the TCC (Transparency, Consent, and Control) permissions assigned to Canva.