Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pdfme
Pdfme schemas |
|
| Vendors & Products |
Pdfme
Pdfme schemas |
Mon, 31 Aug 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | @pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the SVG schema plugin that renders user-supplied SVG content directly to innerHTML without sanitization. Attackers can inject malicious SVG with embedded scripts, event handlers, or foreignObject elements to execute arbitrary JavaScript in users' browsers when viewing or filling templates. | |
| Title | @pdfme/schemas before 5.5.9 Cross-Site Scripting via SVG | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-31T10:50:12.466Z
Reserved: 2026-08-31T08:37:53.170Z
Link: CVE-2026-82868
Updated: 2026-08-31T10:50:04.674Z
Status : Received
Published: 2026-08-31T09:17:07.553
Modified: 2026-08-31T11:16:40.927
Link: CVE-2026-82868
No data.
OpenCVE Enrichment
Updated: 2026-08-31T11:18:35Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')