Vulnerabilities > PDF Image Project

DATE CVE VULNERABILITY TITLE RISK
2020-02-28 CVE-2020-8132 Improper Input Validation vulnerability in Pdf-Image Project Pdf-Image
Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.
network
low complexity
pdf-image-project CWE-20
critical
9.8
2018-06-01 CVE-2018-3757 OS Command Injection vulnerability in Pdf-Image Project Pdf-Image 2.0.0
Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter.
network
low complexity
pdf-image-project CWE-78
critical
9.8