Skip to main content

Vendor/product archive

cnblogs / pdfpatcher CVEs

Beta · best-effort

2 CVEs tagged to cnblogs / pdfpatcher0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2025-63918

Published Nov 17, 2025

PDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attackers to upload arbitrary files to arbitrary locations.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-63917

Published Nov 17, 2025

PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) references. The application uses .NET's XmlDocument class wit…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1