canva CVE Vulnerabilities & Metrics

Focus on canva vulnerabilities and metrics.

Last updated: 29 Mar 2026, 22:25 UTC

About canva Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with canva. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total canva CVEs: 19
Earliest CVE date: 17 Mar 2026, 19:15 UTC
Latest CVE date: 17 Mar 2026, 19:16 UTC

Latest CVE reference: CVE-2026-22882

Rolling Stats

30-day Count (Rolling): 19
365-day Count (Rolling): 19

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical canva CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.0

Max CVSS: 0

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 19
4.0-6.9 0
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS canva CVEs

These are the five CVEs with the highest CVSS scores for canva, sorted by severity first and recency.

All CVEs for canva

CVE-2026-22882 canva vulnerability CVSS: 0 17 Mar 2026, 19:16 UTC

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

CVE-2026-20726 canva vulnerability CVSS: 0 17 Mar 2026, 19:16 UTC

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

CVE-2025-66633 canva vulnerability CVSS: 0 17 Mar 2026, 19:16 UTC

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

CVE-2025-66617 canva vulnerability CVSS: 0 17 Mar 2026, 19:16 UTC

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

CVE-2025-66503 canva vulnerability CVSS: 0 17 Mar 2026, 19:15 UTC

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

CVE-2025-66342 canva vulnerability CVSS: 0 17 Mar 2026, 19:15 UTC

A type confusion vulnerability exists in the EMF functionality of Canva Affinity. A specially crafted EMF file can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution.

CVE-2025-66042 canva vulnerability CVSS: 0 17 Mar 2026, 19:15 UTC

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

CVE-2025-66000 canva vulnerability CVSS: 0 17 Mar 2026, 19:15 UTC

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

CVE-2025-65119 canva vulnerability CVSS: 0 17 Mar 2026, 19:15 UTC

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

CVE-2025-64776 canva vulnerability CVSS: 0 17 Mar 2026, 19:15 UTC

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

CVE-2025-64735 canva vulnerability CVSS: 0 17 Mar 2026, 19:15 UTC

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

CVE-2025-64733 canva vulnerability CVSS: 0 17 Mar 2026, 19:15 UTC

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

CVE-2025-64301 canva vulnerability CVSS: 0 17 Mar 2026, 19:15 UTC

An out‑of‑bounds write vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out‑of‑bounds write, potentially leading to code execution.

CVE-2025-62500 canva vulnerability CVSS: 0 17 Mar 2026, 19:15 UTC

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

CVE-2025-62403 canva vulnerability CVSS: 0 17 Mar 2026, 19:15 UTC

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

CVE-2025-61979 canva vulnerability CVSS: 0 17 Mar 2026, 19:15 UTC

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

CVE-2025-61952 canva vulnerability CVSS: 0 17 Mar 2026, 19:15 UTC

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

CVE-2025-58427 canva vulnerability CVSS: 0 17 Mar 2026, 19:15 UTC

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

CVE-2025-47873 canva vulnerability CVSS: 0 17 Mar 2026, 19:15 UTC

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.