Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

parallax — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting parallax. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Parallax is primarily a JavaScript library used for creating parallax scrolling effects in web design. Historically, it has been associated with multiple cross-site scripting (XSS) vulnerabilities due to improper input sanitization, as well as remote code execution (RCE) flaws in certain versions. Privilege escalation vulnerabilities have also been documented in environments where parallax is integrated with server-side components. The library's 12 CVEs reveal a pattern of insufficient input validation and insecure default configurations. While no major public security incidents have been widely reported, the consistent discovery of vulnerabilities underscores the importance of proper implementation and regular updates when using parallax in production environments.

Top products by parallax: jsPDF filament-comments
CVE ID Title CVSS Severity Published
CVE-2026-90943 parallax filament-comments through 3.0.0 Stored XSS via Comment Body — filament-comments CWE-79 8.7 High 2026-09-14
CVE-2026-31938 jsPDF has HTML Injection in New Window paths — jsPDF CWE-79 9.6 Critical 2026-03-18
CVE-2026-31898 jsPDF has a PDF Object Injection via FreeText color — jsPDF CWE-116 8.1 High 2026-03-18
CVE-2026-25940 jsPDF's PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property) — jsPDF CWE-116 8.1 High 2026-02-19
CVE-2026-25755 jsPDF has PDF Object Injection via Unsanitized Input in addJS Method — jsPDF CWE-94 8.1 High 2026-02-19
CVE-2026-25535 jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions — jsPDF CWE-400 8.7 High 2026-02-19
CVE-2026-24040 jsPDF has a Shared State Race Condition in addJS Plugin — jsPDF CWE-362 9.3AI Critical AI 2026-02-02
CVE-2026-24043 jsPDF Affected by Stored XMP Metadata Injection (Spoofing & Integrity Violation) — jsPDF CWE-74 7.6AI High AI 2026-02-02
CVE-2026-24133 jsPDF Affected by Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder — jsPDF CWE-770 6.5AI Medium AI 2026-02-02
CVE-2026-24737 jsPDF has a PDF Injection in AcroFormChoiceField which allows Arbitrary JavaScript Execution — jsPDF CWE-116 8.1 High 2026-02-02
CVE-2025-68428 jsPDF has Local File Inclusion/Path Traversal vulnerability — jsPDF CWE-35 9.2 Critical 2026-01-05
CVE-2025-57810 jsPDF Parsing of Corrupt PNGs Leads to Potential Denial of Service (DoS) — jsPDF CWE-20 6.5AI Medium AI 2025-08-26
CVE-2025-29907 jsPDF Bypass Regular Expression Denial of Service (ReDoS) — jsPDF CWE-400 6.5 - 2025-03-18

This page lists every published CVE security advisory associated with parallax. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.