Known Vulnerabilities for D8s-pdfs by Democritus
Listed below are 1 of the newest known vulnerabilities associated with "D8s-pdfs" by "Democritus".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-31938 json | jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the `out... | Not Provided | 2026-03-18 | 2026-07-20 |
| CVE-2026-31898 json | jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation... | Not Provided | 2026-03-18 | 2026-07-20 |
| CVE-2026-31017 json | A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Fra... | Not Provided | 2026-04-08 | 2026-07-05 |
| CVE-2026-25940 json | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acroform mod... | Not Provided | 2026-02-19 | 2026-07-20 |
| CVE-2026-25755 json | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows ... | Not Provided | 2026-02-19 | 2026-07-20 |
| CVE-2026-25535 json | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `addImage` metho... | Not Provided | 2026-02-19 | 2026-07-20 |
| CVE-2026-24737 json | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform mod... | Not Provided | 2026-02-02 | 2026-07-20 |
| CVE-2025-68428 json | jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile... | Not Provided | 2026-01-05 | 2026-07-20 |
| CVE-2025-60378 json | Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoice... | Not Provided | 2025-10-10 | 2026-07-05 |
| CVE-2022-41387 json | The d8s-pdfs package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third par... | 9.8 - CRITICAL | 2022-10-11 | 2023-05-15 |