PT-2026-33506 · Unknown · Stirling-Pdf

CVE-2026-33436

·

Published

2026-04-17

·

Updated

2026-05-13

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Stirling-PDF versions prior to 2.0.0
Description File upload endpoints render user-supplied filenames directly into HTML using unsafe methods such as innerHTML without sanitization. This allows an attacker to craft a file with a malicious filename containing JavaScript that executes in the browser context of the user performing the upload, leading to reflected Cross-Site Scripting (XSS), which is a technique where malicious scripts are injected into otherwise trusted websites.
Recommendations Update to version 2.0.0.

Exploit

Fix

XSS

Improper Encoding or Escaping of Output

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33436
GHSA-Q5J3-4M5W-WP75

Affected Products

Stirling-Pdf