CVE Feed

    Dashboard / CVE / CVE-2026-82865

    CVE-2026-82865

    pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in the multiVariableText property panel that assigns unsanitized i18n label values to innerHTML. Attackers who control label overrides through options.labels can inject arbitrary JavaScript that executes when users open the Designer and select a multiVariableText field without variable placeholders.

    Published:Aug 31, 2026
    Last Modified:Aug 31, 2026
    EPS:Aug 31, 2026
    EPSS Score:0.00127
    CVSS Score:4.4

    Affected Products

    Vendor
    Pdfme
    Product
    Schemas

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High