PT-2026-33506 · Unknown · Stirling-Pdf

Published

2026-04-17

·

Updated

2026-05-13

·

CVE-2026-33436

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Stirling-PDF versions prior to 2.0.0
Description File upload endpoints render user-supplied filenames directly into HTML using unsafe methods such as innerHTML without sanitization. This allows an attacker to craft a file with a malicious filename containing JavaScript that executes in the browser context of the user performing the upload, leading to reflected Cross-Site Scripting (XSS), which is a technique where malicious scripts are injected into otherwise trusted websites.
Recommendations Update to version 2.0.0.

Exploit

Fix

XSS

Improper Encoding or Escaping of Output

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-33436

Affected Products

Stirling-Pdf