Cross-Site Scripting Vulnerability in pdfme Schemas by PDFMe
CVE-2026-82865

2.1LOW

Key Information:

Vendor

PDFme

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82865?

The pdfme schemas prior to version 5.5.10 contain a vulnerability that allows for cross-site scripting via the multiVariableText property panel. This vulnerability arises from the assignment of unsanitized internationalization (i18n) label values to innerHTML. Attackers able to control label overrides through the options.labels can exploit this flaw to inject arbitrary JavaScript. This malicious script executes when users access the Designer and select a multiVariableText field devoid of variable placeholders, resulting in potential unauthorized actions or data exposure during standard operations.

Affected Version(s)

schemas 0 < 5.5.10

schemas 5.5.10

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

offset
.