Product
parall jspdf
15 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-31938
CVE-2026-31898
CVE-2026-25940
CVE-2026-25755
CVE-2026-25535
CVE-2026-24737
CVE-2026-24133
CVE-2026-24043
CVE-2026-24040
CVE-2025-68428
CVE-2025-57810
CVE-2025-29907
CVE-2021-23353
CVE-2020-7691
CVE-2020-7690
< 4.2.1
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the
options argument of the output< 4.2.1
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the
createAnnotation met< 4.2.0
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acroform module a
< 4.2.0
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the
addJS method allows an at< 4.2.0
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the
addImage method res< 4.1.0
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module a
< 4.1.0
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addImage method resul
< 4.1.0
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addMetadata function
< 4.1.0
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, the addJS method in the jspdf Node.js build utilizes a shared m
< 4.0.0
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile meth
< 3.0.2
jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage method resul
< 3.0.1
jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.1, user control of the first argument of the addImage method resul
< 2.3.1
This affects the package jspdf before 2.3.1. ReDoS is possible via the addImage function.
all versions
In all versions of the package jspdf, it is possible to use <<script>script> in order to go over the filtering regex.
< 2.0.0
All affected versions <2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS). It is possible to inject JavaScript co