Vulnerabilities (CVE)

Filtered by vendor Parall Subscribe
Filtered by product Jspdf
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-23353 1 Parall 1 Jspdf 2024-11-21 5.0 MEDIUM 5.9 MEDIUM
This affects the package jspdf before 2.3.1. ReDoS is possible via the addImage function.
CVE-2020-7691 1 Parall 1 Jspdf 2024-11-21 4.3 MEDIUM 6.3 MEDIUM
In all versions of the package jspdf, it is possible to use <<script>script> in order to go over the filtering regex.
CVE-2020-7690 1 Parall 1 Jspdf 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
All affected versions <2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS). It is possible to inject JavaScript code via the html method.