Home/Product/parall jspdf
Product

parall jspdf

15 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-31938
< 4.2.1
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the options argument of the output
9.6CRITICAL
CVE-2026-31898
< 4.2.1
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the createAnnotation met
8.1HIGH
CVE-2026-25940
< 4.2.0
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acroform module a
8.1HIGH
CVE-2026-25755
< 4.2.0
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the addJS method allows an at
8.1HIGH
CVE-2026-25535
< 4.2.0
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the addImage method res
7.5HIGH
CVE-2026-24737
< 4.1.0
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module a
8.1HIGH
CVE-2026-24133
< 4.1.0
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addImage method resul
6.5MEDIUM
CVE-2026-24043
< 4.1.0
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addMetadata function
5.4MEDIUM
CVE-2026-24040
< 4.1.0
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, the addJS method in the jspdf Node.js build utilizes a shared m
4.8MEDIUM
CVE-2025-68428
< 4.0.0
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile meth
7.5HIGH
CVE-2025-57810
< 3.0.2
jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage method resul
7.5HIGH
CVE-2025-29907
< 3.0.1
jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.1, user control of the first argument of the addImage method resul
7.5HIGH
CVE-2021-23353
< 2.3.1
This affects the package jspdf before 2.3.1. ReDoS is possible via the addImage function.
5.9MEDIUM
CVE-2020-7691
all versions
In all versions of the package jspdf, it is possible to use <<script>script> in order to go over the filtering regex.
6.3MEDIUM
CVE-2020-7690
< 2.0.0
All affected versions <2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS). It is possible to inject JavaScript co
6.1MEDIUM
threatengine.sh