Pdfforge develops PDF editing and conversion software, with its vulnerability footprint centered on the PDF Architect product and characterized by memory-safety concerns, path-traversal issues, and cryptographic-signature validation weaknesses typical of file-handling utilities. The observed weakness classes reflect both the parsing complexity of PDF documents and the user-interaction model of desktop applications, where UI-related flaws can lead to unintended file operations. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pdfforge over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14420HIGH pdfforge PDF Architect CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in | Dec 23, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-14419HIGH pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected inst | Dec 23, 2025 | 7.8 | 25 | NO | NO |
CVE-2018-19150HIGH Memory corruption in PDMODELProvidePDModelHFT in pdmodel.dll in pdfforge PDF Architect 6 allows remote attackers to cause a denial of service (application crash) or possibly have u | Nov 10, 2018 | 7.8 | 25 | NO | NO |
CVE-2025-14417HIGH pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa | Dec 23, 2025 | 7.8 | 24 | NO | NO |
CVE-2025-14418HIGH pdfforge PDF Architect XLS File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal | Dec 23, 2025 | 7.0 | 23 | NO | NO |
CVE-2025-14416HIGH pdfforge PDF Architect DOC File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal | Dec 23, 2025 | 7.0 | 23 | NO | NO |
CVE-2018-18689MEDIUM The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping | Jan 7, 2021 | 5.3 | 21 | NO | NO |
CVE-2025-14421MEDIUM pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on aff | Dec 23, 2025 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pdfforge.
Media articles that mention a CVE ID that affects a product developed by Pdfforge — matched by CVE ID, not by vendor name.