DocumentCloud's vulnerability footprint is concentrated in its document-processing and web-display tooling, particularly products such as Karteek DocSplit and its core platform, which handle user-supplied documents and render content in web browsers. The recurring exposure centers on application-layer input handling: cross-site scripting in document rendering and OS command injection in processing pipelines reflect the risks inherent to parsing and executing untrusted document formats. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Documentcloud over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-2807MEDIUM Cross-site scripting (XSS) vulnerability in js/window.php in the Navis DocumentCloud plugin before 0.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTM | Sep 1, 2015 | 4.3 | 23 | NO | YES |
CVE-2013-1933HIGH The extract_from_ocr function in lib/docsplit/text_extractor.rb in the Karteek Docsplit (karteek-docsplit) gem 0.5.4 for Ruby allows context-dependent attackers to execute arbitrar | Apr 25, 2013 | 9.3 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Documentcloud.
Media articles that mention a CVE ID that affects a product developed by Documentcloud — matched by CVE ID, not by vendor name.