Flowpaper is a focused vendor of document-conversion and web-based PDF-rendering solutions, with its vulnerability footprint concentrated in a small product portfolio including PDF2JSON, FlexPaper, and Flowpaper itself. The vendor's exposure recurs through memory-safety and input-handling weakness classes, including out-of-bounds reads and writes, NULL-pointer dereferences, and cross-site scripting, reflecting the parsing complexity of PDF processing and the web-presentation layer. A meaningful share of the vendor's disclosures reach serious severity, particularly those affecting document-parsing and rendering operations where memory corruption can lead to denial of service or code execution. Defenders deploying these products in document-conversion pipelines or embedded viewers should prioritize updates targeting memory-safety fixes and treat parser-adjacent flaws as high-impact; current exploitation status and detailed severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flowpaper over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11686CRITICAL The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php. | Jul 3, 2019 | 9.8 | 77 | NO | YES |
CVE-2020-23878CRITICAL pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch. | Nov 10, 2021 | 9.8 | 30 | NO | NO |
CVE-2018-14947HIGH An issue has been found in PDF2JSON 0.69. XmlFontAccu::CSStyle in XmlFonts.cc has Mismatched Memory Management Routines (operator new [] versus operator delete). | Aug 5, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-14946HIGH An issue has been found in PDF2JSON 0.69. The HtmlString class in ImgOutputDev.cc has Mismatched Memory Management Routines (malloc versus operator delete). | Aug 5, 2018 | 8.8 | 26 | NO | NO |
CVE-2020-23879HIGH pdf2json v0.71 was discovered to contain a NULL pointer dereference in the component ObjectStream::getObject. | Nov 10, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-19475MEDIUM An issue has been found in function CCITTFaxStream::lookChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid write of size 2 . | Jul 21, 2021 | 5.5 | 20 | NO | NO |
CVE-2020-19473MEDIUM An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an uncaught floating point exception. | Jul 21, 2021 | 5.5 | 20 | NO | NO |
CVE-2020-19470MEDIUM An issue has been found in function DCTStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a NULL pointer dereference (invalid read of size 1 | Jul 21, 2021 | 5.5 | 20 | NO | NO |
CVE-2020-19468MEDIUM An issue has been found in function EmbedStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a null pointer derefenrece (invalid read of size | Jul 21, 2021 | 5.5 | 20 | NO | NO |
CVE-2020-19467MEDIUM An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an Illegal Use After Free . | Jul 21, 2021 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flowpaper.
Media articles that mention a CVE ID that affects a product developed by Flowpaper — matched by CVE ID, not by vendor name.