P
Penpot
Security Risk Profile
52
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 3 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from February 19, 2026 to present
3
Total CVEs
3
Critical+High
0
Exploited
2
Unpatched
Threat Assessment
Avg CVSS
7.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
52/100
medium
🆕 2Fresh (<7d)📈 2 in Last 30 Days
Severity Distribution
Critical
0High
3Medium
0Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
XSS
2
2
Path Traversal
1
Most Affected Products
1. Penpot Penpot4
2. Kaleidos Penpot1
Recent Vulnerabilities
See more →CVE-2026-47665
CVSS 8.7high
Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTML
Aug 26, 2026🔧 No Patch
CVE-2026-47666
CVSS 7.6high
Penpot: Stored XSS via custom font family name injected into a @font-face style rule
Aug 26, 2026🔧 No Patch
CVE-2026-26202
CVSS 7.5EPSS 0%high
Penpot has Arbitrary File Read via create-font-variant RPC endpoint
Feb 19, 2026
Monitor Penpot in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.