VendorsParalljspdfany version
Vulnerabilities

Parall ax jsPDF any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2026-25755
jsPDF has PDF Object Injection via Unsanitized Input in addJS Method
Published 2026-02-19 · Modified
9.6EPSS 0.008
CVE-2026-25940
jsPDF's PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property)
Published 2026-02-19 · Modified
9.6EPSS 0.006
CVE-2026-31938
jsPDF has HTML Injection in New Window paths
Published 2026-03-18 · Modified
9.6EPSS 0.004
CVE-2025-68428
jsPDF has Local File Inclusion/Path Traversal vulnerability
Published 2026-01-05 · Modified
9.2EPSS 0.022
CVE-2026-25535
jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions
Published 2026-02-19 · Modified
8.7EPSS 0.009
CVE-2025-57810
jsPDF Parsing of Corrupt PNGs Leads to Potential Denial of Service (DoS)
Published 2025-08-26 · Analyzed
8.7EPSS 0.007
CVE-2025-29907
jsPDF Bypass Regular Expression Denial of Service (ReDoS)
Published 2025-03-18 · Analyzed
8.7EPSS 0.007
CVE-2026-24133
jsPDF Affected by Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder
Published 2026-02-02 · Analyzed
8.7EPSS 0.006
CVE-2026-24737
jsPDF has a PDF Injection in AcroFormChoiceField which allows Arbitrary JavaScript Execution
Published 2026-02-02 · Modified
8.3EPSS 0.005
CVE-2026-31898
jsPDF has a PDF Object Injection via FreeText color
Published 2026-03-18 · Modified
8.1EPSS 0.006
CVE-2021-23353
Regular Expression Denial of Service (ReDoS)
Published 2021-03-09 · Modified
7.5EPSS 0.026
CVE-2026-24043
jsPDF Affected by Stored XMP Metadata Injection (Spoofing & Integrity Violation)
Published 2026-02-02 · Analyzed
6.9EPSS 0.003
CVE-2020-7691
Cross-site Scripting (XSS)
Published 2020-07-06 · Modified
6.3EPSS 0.016
CVE-2026-24040
jsPDF has a Shared State Race Condition in addJS Plugin
Published 2026-02-02 · Analyzed
6.3EPSS 0.003
CVE-2020-7690
All affected versions <2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS). It is possible to inject JavaScript code via the html method.
Published 2020-07-06 · Modified
6.1EPSS 0.010