E2pdf develops a modestly represented PDF-generation and manipulation component for web applications, where vulnerabilities concentrate in input-handling and access-control weaknesses such as cross-site scripting, SQL injection, CSRF, and deserialization flaws. The vendor's disclosures tend to acquire public exploit code. Defenders integrating this library should prioritize input validation and authorization controls; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by E2pdf over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0535MEDIUM The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even whe | Mar 7, 2022 | 4.8 | 28 | NO | YES |
CVE-2025-62068MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf e2pdf e2pdf.This issue affects e2pdf: from n/a through <= 1.28.09. | Oct 22, 2025 | 6.5 | 21 | NO | NO |
CVE-2023-50849HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects E2Pdf – | Dec 28, 2023 | 7.2 | 21 | NO | NO |
CVE-2023-46154HIGH Deserialization of Untrusted Data vulnerability in E2Pdf.Com E2Pdf – Export To Pdf Tool for WordPress.This issue affects E2Pdf – Export To Pdf Tool for WordPress: from n/a through | Dec 19, 2023 | 7.2 | 21 | NO | NO |
CVE-2023-6826HIGH The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'import_action' function in versions up to, and including, 1. | Dec 15, 2023 | 7.2 | 20 | NO | NO |
CVE-2026-32442MEDIUM Missing Authorization vulnerability in E2Pdf e2pdf e2pdf allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects e2pdf: from n/a through <= 1.28. | Mar 13, 2026 | 5.0 | 19 | NO | NO |
CVE-2024-43318MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf e2pdf e2pdf.This issue affects e2pdf: from n/a through <= 1.25.05. | Aug 18, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-37415MEDIUM Missing Authorization vulnerability in E2Pdf e2pdf e2pdf.This issue affects e2pdf: from n/a through <= 1.20.27. | Nov 1, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-31373MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in E2Pdf e2pdf e2pdf.This issue affects e2pdf: from n/a through <= 1.20.27. | Apr 15, 2024 | 5.4 | 17 | NO | NO |
CVE-2023-5229MEDIUM The E2Pdf WordPress plugin before 1.20.20 does not sanitize and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even whe | Oct 31, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by E2pdf.
Media articles that mention a CVE ID that affects a product developed by E2pdf — matched by CVE ID, not by vendor name.