Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 17 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, the Get Info workflow in app/core/src/main/resources/templates/security/get-info-on-pdf.html inserts untrusted PDF Title and Author metadata into the summary-text element with innerHTML, allowing a malicious PDF to execute stored cross-site scripting when a user clicks Get Info and to access browser-session data or modify page content. This issue is fixed in version 2.0.0. | |
| Title | Stirling PDF: Stored XSS in Info Summary | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-17T17:58:22.857Z
Reserved: 2026-03-19T18:45:22.437Z
Link: CVE-2026-33437
No data.
Status : Received
Published: 2026-08-17T18:16:35.650
Modified: 2026-08-17T18:16:35.650
Link: CVE-2026-33437
No data.
OpenCVE Enrichment
Updated: 2026-08-17T20:00:04Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')