Stirling develops a PDF processing application where its vulnerability exposure centers on resource exhaustion, path traversal, and input-validation issues reflective of file-handling and web-interface attack surfaces. These weakness classes—including unthrottled resource allocation, directory traversal, cross-site scripting, and relative path attacks—recur across the product line and warrant attention from defenders deploying this tool in untrusted document environments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stirling over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33438MEDIUM Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Versions starting in 2.1.5 and prior to 2.5.2 have Denial of Service (D | Mar 26, 2026 | 6.5 | 24 | NO | NO |
CVE-2026-27625MEDIUM Stirling-PDF is a locally hosted web application that performs various operations on PDF files. In versions prior to 2.5.2, the /api/v1/convert/markdown/pdf endpoint extracts user- | Mar 20, 2026 | 6.5 | 23 | NO | NO |
CVE-2026-34071MEDIUM Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. In version 2.7.3, the /api/v1/convert/eml/pdf endpoint with parameter d | Mar 26, 2026 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stirling.
Media articles that mention a CVE ID that affects a product developed by Stirling — matched by CVE ID, not by vendor name.