| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-60080 | WordPress PDF for Gravity Forms + Drag And Drop Template Builder plugin <= 6.5.0 - PHP Object Injection vulnerability | add-ons.org | PDF for Gravity Forms + Drag And Drop Template Builder | - | - | 2025-12-18 07:22:07 | Deep Dive |
| CVE-2025-12885 | Embed Any Document <= 2.7.10 - Authenticated (Contributor+) Stored Cross-Site Scripting | awsmin | Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files | Medium | 6.4 | 2025-12-18 01:51:13 | Deep Dive |
| CVE-2025-11693 | Export WP Page to Static HTML & PDF <= 4.3.4 - Unauthenticated Cookie Exposure via Log File | recorp | Export WordPress Pages to Static HTML & PDF — Static Site Export | Critical | 9.8 | 2025-12-13 04:31:34 | Deep Dive |
| CVE-2025-14074 | PDF for Contact Form 7 + Drag and Drop Template Builder <= 6.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Duplication | addonsorg | PDF for Contact Form 7 + Drag and Drop Template Builder | Medium | 4.3 | 2025-12-12 09:20:28 | Deep Dive |
| CVE-2025-4970 | BSK PDF Manager <= 3.7.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via SVG File Upload | bannersky | BSK PDF Manager | Medium | 5.5 | 2025-12-12 07:20:34 | Deep Dive |
| CVE-2025-49341 | WordPress PDF Creator Lite plugin <= 1.2 - Cross Site Request Forgery (CSRF) vulnerability | Alex Furr | PDF Creator Lite | - | - | 2025-12-09 14:52:18 | Deep Dive |
| CVE-2025-67589 | WordPress WooCommerce PDF Invoices & Packing Slips plugin <= 4.9.1 - Broken Access Control vulnerability | WP Overnight | WooCommerce PDF Invoices & Packing Slips | Medium | 4.3 | 2025-12-09 14:14:17 | Deep Dive |
| CVE-2025-67469 | WordPress PDF Thumbnail Generator plugin <= 1.4 - Cross Site Request Forgery (CSRF) vulnerability | kubiq | PDF Thumbnail Generator | Medium | 4.3 | 2025-12-09 14:13:56 | Deep Dive |
| CVE-2025-12191 | PDF Catalog for WooCommerce <= 1.1.18 - Authenticated (Subscriber+) Stored Cross-Site Scripting | ovologics | PDF Catalog for WooCommerce | Medium | 5.4 | 2025-12-05 05:31:28 | Deep Dive |
| CVE-2025-66516 | Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected | Apache Software Foundation | Apache Tika core | High | 8.4 | 2025-12-04 16:17:25 | Deep Dive |
| CVE-2025-58113 | PDF-XChange Editor 安全漏洞 | PDF-XChange Co. Ltd | PDF-XChange Editor | Medium | 6.5 | 2025-12-02 15:32:20 | Deep Dive |
| CVE-2025-66019 | pypdf manipulated LZWDecode streams can exhaust RAM | py-pdf | pypdf | - | - | 2025-11-25 23:38:12 | Deep Dive |
| CVE-2025-65108 | md-to-pdf is vulnerable to arbitrary JavaScript code execution when parsing front matter | simonhaenisch | md-to-pdf | Critical | 10.0 | 2025-11-21 21:52:03 | Deep Dive |
| CVE-2025-64269 | WordPress WooCommerce PDF Invoice Builder plugin <= 1.2.150 - Broken Access Control vulnerability | EDGARROJAS | WooCommerce PDF Invoice Builder | Medium | 4.3 | 2025-11-13 09:24:30 | Deep Dive |
| CVE-2025-8397 | Save as PDF Button <= 1.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via restpackpdfbutton Shortcode | restpack | Save as PDF Button | Medium | 6.4 | 2025-11-13 08:27:47 | Deep Dive |
| CVE-2025-62708 | pypdf manipulated LZWDecode streams can exhaust RAM | py-pdf | pypdf | 中危 | - | 2025-10-22 21:36:57 | Deep Dive |
| CVE-2025-62707 | pypdf affected by possible infinite loop when reading DCT inline images without EOF marker | py-pdf | pypdf | - | - | 2025-10-22 21:36:33 | Deep Dive |
| CVE-2025-59552 | WordPress Save as PDF Plugin <= 4.5.2 - Cross Site Scripting (XSS) Vulnerability | Pdfcrowd Dev Team | Save as PDF | Medium | 6.5 | 2025-09-22 18:26:06 | Deep Dive |
| CVE-2025-57945 | WordPress WP Advanced PDF Plugin <= 1.1.7 - Cross Site Scripting (XSS) Vulnerability | cedcommerce | WP Advanced PDF | Medium | 5.9 | 2025-09-22 18:24:56 | Deep Dive |
| CVE-2025-57977 | WordPress Flexible PDF Invoices for WooCommerce & WordPress Plugin <= 6.0.13 - Cross Site Request Forgery (CSRF) Vulnerability | wpdesk | Flexible PDF Invoices for WooCommerce & WordPress | High | 7.1 | 2025-09-22 18:24:33 | Deep Dive |