Known vulnerabilities in the E2pdf plugin
8 security advisories have been published for the E2pdf plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- E2pdf - Path Traversal (CVE-2026-66710) HIGH
- E2pdf - Broken Access Control (CVE-2026-12407) HIGH
- E2pdf - Cross-Site Scripting (XSS) (CVE-2026-7650) MEDIUM
- E2pdf - SQL Injection (CVE-2023-50849) HIGH
- E2pdf - PHP Object Injection (CVE-2023-46154) MEDIUM
- E2pdf - Remote Code Execution (CVE-2023-6826) HIGH
- E2pdf - Cross-Site Scripting (XSS) (CVE-2023-5229) MEDIUM
- E2pdf - Cross-Site Scripting (XSS) (CVE-2022-0535) MEDIUM