Indesign

Vendor:

First CVE: Feb 2, 2006 · Active for 20 years

202
Total CVEs
More Total CVEs than 99% of tracked products
16.8
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Indesign over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 2, 2006
20 years ago
Most Recent CVE
Jun 9, 2026
45 days ago

CVE Severity & Scoring

Indesign202 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local195 (96.5%)
Network6 (3.0%)
Unknown1 (0.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low201 (99.5%)
High0 (0.0%)
Unknown1 (0.5%)
User Interaction
None3 (1.5%)
Unknown1 (0.5%)
Required198 (98.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None201 (99.5%)
Unknown1 (0.5%)

Top CVEs

Signals from CVEs in this product scope (202 CVEs).

202 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Adobe InDesign versions 14.0.1 and below have an unsafe hyperlink processing vulnerability. Successful exploitation could lead to arbitrary code execution. Fixed in versions 13.1.1
May 23, 20199.837NONO
An issue was discovered in Adobe InDesign 12.1.0 and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code e
Dec 9, 20179.834NONO
A memory corruption vulnerability exists in InDesign 15.1.1 (and earlier versions). Insecure handling of a malicious indd file could be abused to cause an out-of-bounds memory acce
Sep 10, 20207.830NONO
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current
Jun 9, 20267.829NONO
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the c
Jun 9, 20267.829NONO
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the cu
Jun 9, 20267.829NONO
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current
Jun 9, 20267.829NONO
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the cu
Jun 9, 20267.829NONO
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the cu
Jun 9, 20267.829NONO
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the c
Jun 9, 20267.829NONO

Exploit Exposure

Signals from CVEs in this product scope (202 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (202 CVEs).

Media Mentions

Signals from CVEs in this product scope (202 CVEs).

Top CNAs Publishing CVEs For Indesign

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
cs314.61.3%00
cs14.61.3%00
20.086.70.3%00
19.025.50.3%00
18.115.50.3%00
18.076.80.3%00