216.73.216.6

CVE-2026-22787

· Published 14/01/2026 17:16 · Modified 14/01/2026 17:16

Labels: CVE-2026-22787 2026-01-14CVE-2026-22787CWE-79[email protected]

Essential information

Published
14/01/2026 17:16
Modified
14/01/2026 17:16
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

html2pdf.js converts any webpage or element into a printable PDF entirely client-side. Prior to 0.14.0, html2pdf.js contains a cross-site scripting (XSS) vulnerability when given a text source rather than an element. This text is not sufficiently sanitized before being attached to the DOM, allowing malicious scripts to be run on the client browser and risking the confidentiality, integrity, and availability of the page's data. This vulnerability has been fixed in [email protected].

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
html2pdf / html2pdf.js cpe:2.3:a:html2pdf:html2pdf.js:<0.14.0:*:*:*:*:*:*:*

References