reportlab records
4 published records for vendor reportlab.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-91 XML Injection (aka Blind XPath Injection)2
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2019-17626No exploit | ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document reportlab · reportlab · CWE-91 | Critical9.8 | — | 10.2% | Oct 16, 2019 |
41Plan | CVE-2019-19450No exploit | paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in reportlab · reportlab · CWE-91 | Critical9.8 | — | 6.0% | Sep 20, 2023 |
32Monitor | CVE-2023-33733Proof of concept | Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file.reportlab · reportlab · CWE-94 | High7.8 | — | 2.1% | Jun 5, 2023 |
26Monitor | CVE-2020-28463No exploit | Server-side Request Forgery (SSRF)reportlab · reportlab · CWE-918 | Medium6.5 | — | 1.5% | Feb 18, 2021 |
- CVE-2019-1762642Plan
ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document
CriticalCVSS 9.8No exploitEPSS 10%reportlab · reportlabOct 16, 2019
- CVE-2019-1945041Plan
paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in
CriticalCVSS 9.8No exploitEPSS 6%reportlab · reportlabSep 20, 2023
- CVE-2023-3373332Monitor
Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file.
HighCVSS 7.8Proof of conceptEPSS 2%reportlab · reportlabJun 5, 2023
- CVE-2020-2846326Monitor
Server-side Request Forgery (SSRF)
MediumCVSS 6.5No exploitEPSS 1%reportlab · reportlabFeb 18, 2021