VulnSea

pdfme has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was August 2026 with 5. The median CVSS is 6.1 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-79 (3). Most affected products: schemas (3), common (1), pdf-lib (1).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
—
Last 90 days
5 prev 0

Products

  • schemas 3
  • common 1
  • pdf-lib 1
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

pdfme vulnerabilities

CVEs affecting pdfme, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-82868Medium· 6.1PoC
1mo ago

@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the SVG schema plugin that renders user-supplied SVG content directly to innerHTML without sanitization

@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the SVG schema plugin that renders user-supplied SVG content directly to innerHTML without sanitization. Attackers can inject malicious SVG with embedded script…

▾ Twilightpdfme · schemasEPSS 0.26%via NVD
CVE-2026-82867Medium· 6.1PoC
1mo ago

@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the Select schema plugin that fails to sanitize option values before interpolating them into HTML via innerHTML

@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the Select schema plugin that fails to sanitize option values before interpolating them into HTML via innerHTML. Attackers can supply malicious templates with c…

▾ Twilightpdfme · schemasEPSS 0.31%via NVD
CVE-2026-82866Medium· 6.8PoC
1mo ago

@pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without validation when basePdf is attacker-controlled

@pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without validation when basePdf is attacker-controlled. Attackers who control the basePdf template…

▾ Twilightpdfme · commonEPSS 0.35%via NVD
CVE-2026-82865Medium· 4.4PoC
1mo ago

pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in the multiVariableText property panel that assigns unsanitized i18n label values to innerHTML

pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in the multiVariableText property panel that assigns unsanitized i18n label values to innerHTML. Attackers who control label overrides through options.labels can i…

▾ Twilightpdfme · schemasEPSS 0.20%via NVD
CVE-2026-82864Medium· 6.5
1mo ago

pdfme pdf-lib versions before 5.5.10 contain an unbounded buffer growth vulnerability in the DecodeStream.ensureBuffer() method that allows attackers to cause denial of service by supplying a crafted PDF with a FlateDecode stream contain…

pdfme pdf-lib versions before 5.5.10 contain an unbounded buffer growth vulnerability in the DecodeStream.ensureBuffer() method that allows attackers to cause denial of service by supplying a crafted PDF with a FlateDecode stream contain…

▾ Sunlitpdfme · pdf-libEPSS 0.44%via NVD
pdfme vulnerabilities (CVEs) · VulnSea