Stored Cross-Site Scripting Vulnerability in Stirling-PDF Web Application
CVE-2026-33437
8.1HIGH
What is CVE-2026-33437?
The Stirling-PDF web application contained a vulnerability that allowed untrusted PDF Title and Author metadata to be inserted into the web application interface. This flaw existed prior to version 2.0.0, where, upon invoking the Get Info workflow, the application inadequately handled this metadata, resulting in the potential execution of malicious scripts. Attackers could exploit this vulnerability to carry out stored cross-site scripting attacks, compromising the security of user browser sessions and altering page content. Users are highly encouraged to update to version 2.0.0 or later to mitigate this risk.
Affected Version(s)
Stirling-PDF < 2.0.0
