Jsreport is a focused report-generation and document-rendering platform that converts templates to PDFs and other formats, with a niche but security-sensitive role in server-side content processing. Its durable vulnerability signal centers on path traversal, code injection, server-side request forgery, and untrusted control-sphere issues that arise from template handling and external resource inclusion, reflecting the inherent risks of dynamic code execution and file-system access in templating engines.
The number and severity of CVEs published that impact products developed by Jsreport over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2583CRITICAL Code Injection in GitHub repository jsreport/jsreport prior to 3.11.3. | May 8, 2023 | 10.0 | 31 | NO | NO |
CVE-2020-8128CRITICAL An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitrary code. | Feb 14, 2020 | 9.8 | 25 | NO | NO |
CVE-2020-7762MEDIUM This affects the package jsreport-chrome-pdf before 1.10.0. | Nov 5, 2020 | 6.5 | 22 | NO | NO |
CVE-2020-7763HIGH This affects the package phantom-html-to-pdf before 0.6.1. | Nov 5, 2020 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jsreport.
Media articles that mention a CVE ID that affects a product developed by Jsreport — matched by CVE ID, not by vendor name.