Canva vulnerabilities
CVEs whose affected-version data names the Canva package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-90860High· 7.1The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView
The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
▾ TwilightCanva · CanvaEPSS 0.18%via NVD
CVE-2026-92839Medium· 4.3Canva Desktop before v1.125.0 performed double decoding in the deeplink handler
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.
▾ SunlitCanva · CanvaEPSS 0.21%via NVD