parall has 7 CVEs on record. The busiest recent month was February 2026 with 4. The median CVSS is 8.1 (high), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-116 (4).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Worst active — by depth score
CVE-2026-25940High· 8.1jsPDF is a library to generate PDFs in JavaScript57CVE-2026-25755High· 8.1jsPDF is a library to generate PDFs in JavaScript57CVE-2025-68428High· 7.5jsPDF is a library to generate PDFs in JavaScript54CVE-2026-31938Critical· 9.6jsPDF is a library to generate PDFs in JavaScript53CVE-2026-31898High· 8.1jsPDF is a library to generate PDFs in JavaScript45
parall vulnerabilities
CVEs affecting parall, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-31938Critical· 9.6jsPDF is a library to generate PDFs in JavaScript
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the `output` function allows attackers to inject arbitrary HTML (such as scripts) into the browser context the created P…
CVE-2026-31898High· 8.1jsPDF is a library to generate PDFs in JavaScript
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation` method allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to p…
CVE-2026-25940High· 8.1PoCjsPDF is a library to generate PDFs in JavaScript
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass u…
CVE-2026-25755High· 8.1PoCjsPDF is a library to generate PDFs in JavaScript
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject arbitrary PDF objects into the generated document. By crafting a payload that escapes the …
CVE-2026-25535High· 7.5jsPDF is a library to generate PDFs in JavaScript
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `addImage` method results in denial of service. If given the possibility to pass unsanitized image data or URLs to the `addImage…
CVE-2026-24737High· 8.1jsPDF is a library to generate PDFs in JavaScript
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass u…
CVE-2025-68428High· 7.5PoCjsPDF is a library to generate PDFs in JavaScript
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal. If given the possibility to pass unsani…