VYPR
Vendor

Canva

Products
3
CVEs
24
Across products
24
Status
Private

Products

3

Recent CVEs

24
View all 24 CVEs →
  • CVE-2026-85085CriSep 4, 2026
    risk 0.62cvss 9.6epss 0.00

    The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.

  • CVE-2026-85094HigSep 4, 2026
    risk 0.57cvss 8.8epss 0.00

    The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.

  • CVE-2025-66342HigMar 17, 2026
    risk 0.51cvss 7.8epss 0.00

    A type confusion vulnerability exists in the EMF functionality of Canva Affinity. A specially crafted EMF file can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution.

  • CVE-2025-64301HigMar 17, 2026
    risk 0.51cvss 7.8epss 0.00

    An out‑of‑bounds write vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out‑of‑bounds write, potentially leading to code execution.

  • CVE-2026-90860HigSep 21, 2026
    risk 0.46cvss 7.1epss 0.00

    The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.

  • CVE-2026-22882MedMar 17, 2026
    risk 0.40cvss 6.1epss 0.00

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

  • CVE-2026-20726MedMar 17, 2026
    risk 0.40cvss 6.1epss 0.00

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

  • CVE-2025-66633MedMar 17, 2026
    risk 0.40cvss 6.1epss 0.00

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

  • CVE-2025-66617MedMar 17, 2026
    risk 0.40cvss 6.1epss 0.00

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

  • CVE-2025-66503MedMar 17, 2026
    risk 0.40cvss 6.1epss 0.00

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

  • CVE-2025-66042MedMar 17, 2026
    risk 0.40cvss 6.1epss 0.00

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

  • CVE-2025-66000MedMar 17, 2026
    risk 0.40cvss 6.1epss 0.00

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

  • CVE-2025-65119MedMar 17, 2026
    risk 0.40cvss 6.1epss 0.00

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

  • CVE-2025-64776MedMar 17, 2026
    risk 0.40cvss 6.1epss 0.00

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

  • CVE-2025-64735MedMar 17, 2026
    risk 0.40cvss 6.1epss 0.00

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

  • CVE-2025-64733MedMar 17, 2026
    risk 0.40cvss 6.1epss 0.00

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

  • CVE-2025-62500MedMar 17, 2026
    risk 0.40cvss 6.1epss 0.00

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

  • CVE-2025-62403MedMar 17, 2026
    risk 0.40cvss 6.1epss 0.00

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

  • CVE-2025-61979MedMar 17, 2026
    risk 0.40cvss 6.1epss 0.00

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

  • CVE-2025-61952MedMar 17, 2026
    risk 0.40cvss 6.1epss 0.00

    An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.