Pdfforge Pdf Architect vulnerabilities
8 known vulnerabilities affecting pdfforge/pdf_architect.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH6MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2025-14418HIGHCVSS 7.0v9.1.74.230302025-12-23
CVE-2025-14418 [HIGH] CWE-356 CVE-2025-14418: pdfforge PDF Architect XLS File Insufficient UI Warning Remote Code Execution Vulnerability. This vu
pdfforge PDF Architect XLS File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The s
cvelistv5nvd
CVE-2025-14419HIGHCVSS 7.8v9.1.74.230302025-12-23
CVE-2025-14419 [HIGH] CWE-119 CVE-2025-14419: pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This
pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The
cvelistv5nvd
CVE-2025-14416HIGHCVSS 7.0v9.1.74.230302025-12-23
CVE-2025-14416 [HIGH] CWE-356 CVE-2025-14416: pdfforge PDF Architect DOC File Insufficient UI Warning Remote Code Execution Vulnerability. This vu
pdfforge PDF Architect DOC File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The s
cvelistv5nvd
CVE-2025-14420HIGHCVSS 7.8v9.1.74.230302025-12-23
CVE-2025-14420 [HIGH] CWE-22 CVE-2025-14420: pdfforge PDF Architect CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability. Thi
pdfforge PDF Architect CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Th
cvelistv5nvd
CVE-2025-14417HIGHCVSS 7.8v9.1.74.230302025-12-23
CVE-2025-14417 [HIGH] CWE-356 CVE-2025-14417: pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerability. This vuln
pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The spe
cvelistv5nvd
CVE-2025-14421MEDIUMCVSS 5.5v9.1.74.230302025-12-23
CVE-2025-14421 [MEDIUM] CWE-125 CVE-2025-14421: pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. Thi
pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a maliciou
cvelistv5nvd
CVE-2018-18689MEDIUMCVSS 5.3v6.0.37v6.1.24.18622021-01-07
CVE-2018-18689 [MEDIUM] CWE-347 CVE-2018-18689: The Portable Document Format (PDF) specification does not provide any information regarding the conc
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations that are not detected by the signature-validation logic. This affects Fox
nvd
CVE-2018-19150HIGHCVSS 7.8v62018-11-10
CVE-2018-19150 [HIGH] CWE-119 CVE-2018-19150: Memory corruption in PDMODELProvidePDModelHFT in pdmodel.dll in pdfforge PDF Architect 6 allows remo
Memory corruption in PDMODELProvidePDModelHFT in pdmodel.dll in pdfforge PDF Architect 6 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because of a "Data from Faulting Address controls Code Flow" issue.
nvd