Sodapdf develops a focused product line centered on PDF editing and conversion tools for desktop and web environments. Its vulnerability profile clusters around file-handling and boundary-management weaknesses—out-of-bounds reads, path traversal, and memory-buffer issues—alongside signature-verification and user-warning gaps that are characteristic of document-processing applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sodapdf over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14412HIGH Soda PDF Desktop XLS File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installation | Dec 23, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-14409HIGH Soda PDF Desktop PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa | Dec 23, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-14415HIGH Soda PDF Desktop Launch Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Dec 23, 2025 | 7.8 | 24 | NO | NO |
CVE-2025-14414HIGH Soda PDF Desktop Word File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio | Dec 23, 2025 | 7.8 | 24 | NO | NO |
CVE-2025-14413HIGH Soda PDF Desktop CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa | Dec 23, 2025 | 7.8 | 24 | NO | NO |
CVE-2025-14406HIGH Soda PDF Desktop Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installatio | Dec 23, 2025 | 7.8 | 24 | NO | NO |
CVE-2018-18689MEDIUM The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping | Jan 7, 2021 | 5.3 | 21 | NO | NO |
CVE-2025-14411MEDIUM Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected | Dec 23, 2025 | 5.5 | 20 | NO | NO |
CVE-2025-14410MEDIUM Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected | Dec 23, 2025 | 5.5 | 20 | NO | NO |
CVE-2025-14407MEDIUM Soda PDF Desktop PDF File Parsing Memory Corruption Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected i | Dec 23, 2025 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sodapdf.
Media articles that mention a CVE ID that affects a product developed by Sodapdf — matched by CVE ID, not by vendor name.