MEDIUMVulnerability

CVE-2026-82865

pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in the multiVariableText property panel that assigns unsanitized i18n label values to innerHTML. Attackers who control label overrides through options.labels can inject arbitrary JavaScript that executes when users open the Designer and select a multiVariableText field without variable placeholders.

Properties

severity
MEDIUM
score
4.4
epss_score
0.00127
cve_id
CVE-2026-82865
signal_observed_at
2026-09-15T21:12:48+00:00
vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
published_at
2026-08-31T09:17:07.110
last_modified
2026-09-10T15:53:23.707
epss_percentile
0.02672

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82865 — Ninja Signal Threat Intelligence | Ninja Signal