๐Ÿ” CVE Alert

CVE-2026-82865

MEDIUM 4.4

pdfme schemas before 5.5.10 Cross-Site Scripting via i18n Label

CVSS Score
4.4
EPSS Score
0.0%
EPSS Percentile
0th

pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in the multiVariableText property panel that assigns unsanitized i18n label values to innerHTML. Attackers who control label overrides through options.labels can inject arbitrary JavaScript that executes when users open the Designer and select a multiVariableText field without variable placeholders.

CWE CWE-79
Vendor pdfme
Product schemas
Published Aug 31, 2026
Stay Ahead of the Next One

Get instant alerts for pdfme schemas

Be the first to know when new medium vulnerabilities affecting pdfme schemas are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

pdfme / schemas
0 < 5.5.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/pdfme/pdfme/security/advisories/GHSA-xgx4-2wgv-4jhm vulncheck.com: https://www.vulncheck.com/advisories/pdfme-schemas-before-5.5.10-cross-site-scripting-via-i18n-label

Credits

๐Ÿ” offset