Pdftron develops document-processing and web-viewing components, notably its WebViewer UI library, that integrate document rendering functionality into broader applications and platforms. The recurring vulnerability signal centers on web-layer input-handling issues such as cross-site scripting, alongside memory-safety concerns reflected in use-after-free conditions; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pdftron over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24960HIGH A use after free vulnerability was discovered in PDFTron SDK version 9.2.0. A crafted PDF can overwrite RIP with data previously allocated on the heap. This issue affects: PDFTron | Mar 10, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-39307MEDIUM PDFTron's WebViewer UI 8.0 or below renders dangerous URLs as hyperlinks in supported documents, including JavaScript URLs, allowing the execution of arbitrary JavaScript code. | Sep 15, 2021 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pdftron.
Media articles that mention a CVE ID that affects a product developed by Pdftron — matched by CVE ID, not by vendor name.