Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pdfme
Pdfme schemas |
|
| Vendors & Products |
Pdfme
Pdfme schemas |
Mon, 31 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | @pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the Select schema plugin that fails to sanitize option values before interpolating them into HTML via innerHTML. Attackers can supply malicious templates with crafted option values containing HTML and JavaScript to execute arbitrary code in users' browsers. | |
| Title | @pdfme/schemas before 5.5.9 Cross-Site Scripting via Select | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-01T15:05:25.188Z
Reserved: 2026-08-31T08:37:53.170Z
Link: CVE-2026-82867
Updated: 2026-09-01T15:05:18.522Z
Status : Received
Published: 2026-08-31T09:17:07.410
Modified: 2026-09-01T15:17:37.300
Link: CVE-2026-82867
No data.
OpenCVE Enrichment
Updated: 2026-08-31T21:21:50Z
