Fabricjs maintains a JavaScript canvas-rendering library focused on interactive drawing and manipulation capabilities in web applications. The vendor's observed vulnerability profile centers on output-encoding and cross-site scripting weaknesses, reflecting the inherent challenges of sanitizing user-controlled content in browser-based graphics manipulation; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fabricjs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-44311MEDIUM Fabric.js is a Javascript HTML5 canvas library. Prior to 7.4.0, a potential Cross-Site Scripting (XSS) vulnerability exists in Fabric.js due to improper escaping of user-controlled | Jun 22, 2026 | 6.1 | 25 | NO | NO |
CVE-2026-27013MEDIUM Fabric.js is a Javascript HTML5 canvas library. Prior to version 7.2.0, Fabric.js applies `escapeXml()` to text content during SVG export (`src/shapes/Text/TextSVGExportMixin.ts:18 | Feb 19, 2026 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fabricjs.
Media articles that mention a CVE ID that affects a product developed by Fabricjs — matched by CVE ID, not by vendor name.