pkg:npm/jspdf
15 total CVEsCRITICAL1HIGH6MEDIUM2
✅ Check your installed version
All known vulnerabilities
- from 0, < 4.2.1
- from 0, < 4.2.1
- HIGH8.1CVE-2026-25940jsPDF has a PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property)from 0, < 4.2.0
- from 0, < 4.2.0
- HIGH8.1CVE-2026-24737jsPDF has PDF Injection in AcroFormChoiceField that allows Arbitrary JavaScript Executionfrom 0, < 4.1.0
- from 0, < 3.0.2
- from 0, < 2.3.1
- from 0, < 2.0.0
- from 0, < 2.0.0
- —CVE-2026-25535jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensionsfrom 0, < 4.2.0
- —CVE-2026-24133jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoderfrom 0, < 4.1.0
- from 0, < 4.1.0
- from 0, < 4.1.0
- from 0, < 4.0.0
- from 0, < 3.0.1