Stirling PDF is a document-processing utility with a focused but notably leveraged vulnerability profile: despite a narrow product scope, the tool's file-handling and web-interface functionality creates a significant attack surface. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit code, with the exposure concentrated in server-side request forgery, cross-site scripting, and input-validation weaknesses that are characteristic of web-based document converters and processors. Defenders should prioritize updates for this tool and restrict network access where feasible; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stirlingpdf over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-55161CRITICAL Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/convert/markdown/pdf endpoint to conv | Aug 11, 2025 | 9.8 | 44 | NO | YES |
CVE-2025-55150CRITICAL Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/convert/html/pdf endpoint to convert | Aug 11, 2025 | 9.8 | 44 | NO | YES |
CVE-2025-55151CRITICAL Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, the "convert file to pdf" functionality (/api/v1/convert/fil | Aug 11, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-46568HIGH Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Prior to version 0.45.0, Stirling-PDF is vulnerable to SSRF-induced arb | May 1, 2025 | 7.5 | 22 | NO | NO |
CVE-2026-33436MEDIUM Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. In versions prior to 2.0.0, file upload endpoints render user-supplied filenames | Apr 17, 2026 | 6.1 | 21 | NO | NO |
CVE-2024-9075MEDIUM A vulnerability was found in Stirling-Tools Stirling-PDF up to 0.28.3. It has been declared as problematic. This vulnerability affects unknown code of the component Markdown-to-PDF | Sep 21, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stirlingpdf.
Media articles that mention a CVE ID that affects a product developed by Stirlingpdf — matched by CVE ID, not by vendor name.