{"id":"CVE-2020-7690","details":"All affected versions \u003c2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS). It is possible to inject JavaScript code via the html method.","aliases":["GHSA-vh59-v9r5-4mh4","SNYK-JS-JSPDF-575256"],"modified":"2026-07-08T06:09:03.401005Z","published":"2020-07-06T13:15:10.610Z","references":[{"type":"EVIDENCE","url":"https://github.com/MrRio/jsPDF/issues/2795"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JS-JSPDF-575256"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/parallax/jspdf","events":[{"introduced":"0"},{"fixed":"4497d22f4bcbcc794cc8364e26b1986d787ed753"}],"database_specific":{"cpe":"cpe:2.3:a:parall:jspdf:*:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.0.0"}],"source":"CPE_RANGE"}}],"versions":["v1.5.3","v1.5.2","v1.5.1","v1.5.0","v1.4.1","v1.4.0","v.1.4.0","v1.3.5","1.3.4","v1.3.4","v1.3.3","v1.3.0","v1.2.61","v1.2.60","1.1.135","v1.0.272","v1.0.178","v1.0.150","v1.0.138","v1.0.119","v1.0.116","v1.0.115","v1.0.106","v0.9.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-7690.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}