VYPR
Vendor

Pdfme

Products
1
CVEs
6
Across products
6
Status
Private

Products

1

Recent CVEs

6
  • CVE-2026-82866MedAug 31, 2026
    risk 0.37cvss 6.8epss 0.00

    @pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without validation when basePdf is attacker-controlled. Attackers who control the basePdf template field can force servers or clients to…

  • CVE-2026-82864MedAug 31, 2026
    risk 0.35cvss 6.5epss 0.00

    pdfme pdf-lib versions before 5.5.10 contain an unbounded buffer growth vulnerability in the DecodeStream.ensureBuffer() method that allows attackers to cause denial of service by supplying a crafted PDF with a FlateDecode stream containing a decompression bomb. Attackers can…

  • CVE-2026-82868MedAug 31, 2026
    risk 0.33cvss 6.1epss 0.00

    @pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the SVG schema plugin that renders user-supplied SVG content directly to innerHTML without sanitization. Attackers can inject malicious SVG with embedded scripts, event handlers, or foreignObject…

  • CVE-2026-82867MedAug 31, 2026
    risk 0.33cvss 6.1epss 0.00

    @pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the Select schema plugin that fails to sanitize option values before interpolating them into HTML via innerHTML. Attackers can supply malicious templates with crafted option values containing HTML and…

  • CVE-2025-53626MedJul 10, 2025
    risk 0.33cvss 6.1epss 0.00

    pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabilities allowing sandbox escape leading to XSS and prototype pollution attacks. This vulnerability is fixed in 5.4.1.

  • CVE-2026-82865MedAug 31, 2026
    risk 0.22cvss 4.4epss 0.00

    pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in the multiVariableText property panel that assigns unsanitized i18n label values to innerHTML. Attackers who control label overrides through options.labels can inject arbitrary JavaScript that executes…