PMD Project maintains a static-analysis tool for code quality assessment that, despite a narrow product scope, is embedded across development environments and continuous integration pipelines. The tool's observed vulnerability profile centers on its web-facing interfaces and XML processing capabilities, with durable exposure patterns around cross-site scripting and XML external entity injection. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pmd Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-7722HIGH PMD 5.8.1 and earlier processes XML external entities in ruleset files it parses as part of the analysis process, allowing attackers tampering it (either by direct modification or | Feb 11, 2019 | 8.1 | 25 | NO | NO |
CVE-2026-28338MEDIUM PMD is an extensible multilanguage static code analyzer. Prior to version 7.22.0, PMD's `vbhtml` and `yahtml` report formats insert rule violation messages into HTML output without | Feb 27, 2026 | 6.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pmd Project.
Media articles that mention a CVE ID that affects a product developed by Pmd Project — matched by CVE ID, not by vendor name.