CVE Tools

Parallax

7 CVEs tracked since 2026. Since Feb 2026, none of them reached CISA KEV.

Parallax CVEs per month

Feb 2026 to Feb 2026. Point at a month, or focus the strip and use the arrow keys.
Parallax CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-0270

Products

The products that kept showing up in Parallax's monthly top three, with their CVEs summed over those months.

  1. Jspdf71 month

Latest CVEs

The 13 most recently published vulnerabilities affecting Parallax.

  1. CVE-2026-90943parallax filament-comments through 3.0.0 Stored XSS via Comment Body8.7
  2. CVE-2026-31938jsPDF has HTML Injection in New Window paths9.6
  3. CVE-2026-31898jsPDF has a PDF Object Injection via FreeText color8.1
  4. CVE-2026-25940jsPDF's PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property)8.1
  5. CVE-2026-25755jsPDF has PDF Object Injection via Unsanitized Input in addJS Method8.1
  6. CVE-2026-25535jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions7.5
  7. CVE-2026-24040jsPDF has a Shared State Race Condition in addJS Plugin4.8
  8. CVE-2026-24043jsPDF Affected by Stored XMP Metadata Injection (Spoofing & Integrity Violation)5.4
  9. CVE-2026-24133jsPDF Affected by Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder6.5
  10. CVE-2026-24737jsPDF has a PDF Injection in AcroFormChoiceField which allows Arbitrary JavaScript Execution8.1
  11. CVE-2025-68428jsPDF has Local File Inclusion/Path Traversal vulnerability7.5
  12. CVE-2025-57810jsPDF Parsing of Corrupt PNGs Leads to Potential Denial of Service (DoS)7.5
  13. CVE-2025-29907jsPDF Bypass Regular Expression Denial of Service (ReDoS)7.5

The record

Peak rank
#158 in Feb 2026
Busiest month shown
Feb 2026, 7 CVEs
Months with a KEV entry
0 since Feb 2026
Monthly snapshots
1 since 2026
Parallax's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store