E2Pdf records
9 published records for vendor e2pdf.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 66.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-502 Deserialization of Untrusted Data1
- CWE-862 Missing Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
28Monitor | CVE-2023-6826No exploit | E2Pdf <= 1.20.25 - Authenticated (Administrator+) Arbitrary File Uploade2pdf · e2pdf · CWE-434 | High7.2 | — | 1.3% | Dec 15, 2023 |
28Monitor | CVE-2023-46154No exploit | WordPress e2pdf Plugin <= 1.20.18 is vulnerable to PHP Object Injectione2pdf · e2pdf · CWE-502 | High7.2 | — | 0.7% | Dec 18, 2023 |
28Monitor | CVE-2023-50849No exploit | WordPress e2pdf Plugin <= 1.20.23 is vulnerable to SQL Injectione2pdf · e2pdf · CWE-89 | High7.2 | — | 0.5% | Dec 28, 2023 |
26Monitor | CVE-2025-62068No exploit | WordPress e2pdf plugin <= 1.28.09 - Cross Site Scripting (XSS) vulnerabilitye2pdf · e2pdf · CWE-79 | Medium6.5 | — | 0.2% | Oct 22, 2025 |
21Monitor | CVE-2024-37415No exploit | WordPress E2Pdf plugin <= 1.20.27 - Broken Access Control vulnerabilitye2pdf · e2pdf · CWE-862 | Medium5.4 | — | 0.3% | Nov 1, 2024 |
21Monitor | CVE-2024-43318No exploit | WordPress E2Pdf – Export To Pdf Tool for WordPress plugin <= 1.25.05 - Cross Site Scripting (XSS) vulnerabilitye2pdf · e2pdf · CWE-79 | Medium5.4 | — | 0.3% | Aug 18, 2024 |
21Monitor | CVE-2024-31373No exploit | WordPress E2Pdf plugin <= 1.20.27 - Cross Site Request Forgery (CSRF) vulnerabilitye2pdf · e2pdf · CWE-352 | Medium5.4 | — | 0.2% | Apr 15, 2024 |
19Monitor | CVE-2022-0535Proof of concept | E2Pdf < 1.16.45 - Admin+ Stored Cross-Site Scripting (XSS)e2pdf · e2pdf · CWE-79 | Medium4.8 | — | 1.3% | Mar 7, 2022 |
19Monitor | CVE-2023-5229No exploit | E2Pdf < 1.20.20 - Admin+ Stored Cross-Site Scripinge2pdf · e2pdf · CWE-79 | Medium4.8 | — | 0.4% | Oct 31, 2023 |
- CVE-2023-682628Monitor
E2Pdf <= 1.20.25 - Authenticated (Administrator+) Arbitrary File Upload
HighCVSS 7.2No exploitEPSS 1%e2pdf · e2pdfDec 15, 2023
- CVE-2023-4615428Monitor
WordPress e2pdf Plugin <= 1.20.18 is vulnerable to PHP Object Injection
HighCVSS 7.2No exploitEPSS 1%e2pdf · e2pdfDec 18, 2023
- CVE-2023-5084928Monitor
WordPress e2pdf Plugin <= 1.20.23 is vulnerable to SQL Injection
HighCVSS 7.2No exploitEPSS 1%e2pdf · e2pdfDec 28, 2023
- CVE-2025-6206826Monitor
WordPress e2pdf plugin <= 1.28.09 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.5No exploitEPSS 0%e2pdf · e2pdfOct 22, 2025
- CVE-2024-3741521Monitor
WordPress E2Pdf plugin <= 1.20.27 - Broken Access Control vulnerability
MediumCVSS 5.4No exploitEPSS 0%e2pdf · e2pdfNov 1, 2024
- CVE-2024-4331821Monitor
WordPress E2Pdf – Export To Pdf Tool for WordPress plugin <= 1.25.05 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%e2pdf · e2pdfAug 18, 2024
- CVE-2024-3137321Monitor
WordPress E2Pdf plugin <= 1.20.27 - Cross Site Request Forgery (CSRF) vulnerability
MediumCVSS 5.4No exploitEPSS 0%e2pdf · e2pdfApr 15, 2024
- CVE-2022-053519Monitor
E2Pdf < 1.16.45 - Admin+ Stored Cross-Site Scripting (XSS)
MediumCVSS 4.8Proof of conceptEPSS 1%e2pdf · e2pdfMar 7, 2022
- CVE-2023-522919Monitor
E2Pdf < 1.20.20 - Admin+ Stored Cross-Site Scriping
MediumCVSS 4.8No exploitEPSS 0%e2pdf · e2pdfOct 31, 2023