Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Itextpdf

First CVE: Nov 8, 2017Active for: 9 yearsTotal CVEs: 8

iText is a widely embedded PDF-generation and manipulation library whose narrow product footprint masks significant supply-chain reach across enterprise applications, development platforms, and document-processing workflows. Vulnerabilities affecting the vendor skew toward serious outcomes, concentrating in its core iText library through weakness classes including XML external entity injection, resource-exhaustion conditions, command injection, and array-index validation gaps that reflect the complexity of parsing and rendering untrusted document formats. Defenders should prioritize tracking this vendor's advisories and coordinate updates across downstream products that bundle the library, since remediation often depends on application vendors rebuilding; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Itextpdf over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 2017
8 years ago
Most Recent CVE
Nov 26, 2023
971 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-43113CRITICAL
iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in Ghostsc
Dec 15, 20219.833NONO
CVE-2017-9096HIGH
The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a
Nov 8, 20178.833NONO
CVE-2017-20151CRITICAL
A vulnerability classified as problematic was found in iText RUPS. This vulnerability affects unknown code of the file src/main/java/com/itextpdf/rups/model/XfaFile.java. The manip
Dec 30, 20229.830NONO
CVE-2022-24197MEDIUM
iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a Denial of Service (DoS) via a crafted P
Feb 1, 20226.523NONO
CVE-2022-24196MEDIUM
iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, which allows attackers to cause a Denial o
Feb 1, 20226.523NONO
CVE-2022-24198MEDIUM
iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackers to cause a Denial of Service (DoS) via
Feb 1, 20226.522NONO
CVE-2023-6299MEDIUM
A vulnerability, which was classified as problematic, has been found in Apryse iText 8.0.1. This issue affects some unknown processing of the file PdfDocument.java of the component
Nov 26, 20236.520NONO
CVE-2023-6298MEDIUM
A vulnerability classified as problematic was found in Apryse iText 8.0.2. This vulnerability affects the function main of the file PdfDocument.java. The manipulation leads to impr
Nov 26, 20236.520NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
63%
13%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (25.0%)
Unknown0 (0.0%)
Required6 (75.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Itextpdf.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Itextpdf — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Itextpdf's Products

View all 2 CNAs →

Top CWEs