Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dompdf HIGH 7.5
CVE-2026-59941

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on its declared …

Fix: 3.1.6+
Fix from $1,950 2026-07-28
Dompdf HIGH 7.5
CVE-2026-59942

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. An at…

Fix: 3.1.6+
Fix from $1,950 2026-07-28
Dompdf MEDIUM 5.3
CVE-2026-59943

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by Dompdf …

Fix: 3.1.6+
Fix from $1,600 2026-07-28
Dompdf MEDIUM 5.3
CVE-2026-56722

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass this restriction by embed…

Fix: 3.1.6+
Fix from $1,600 2026-07-28
Dompdf HIGH 7.5
CVE-2026-55554

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boundaries with a strpos() pref…

Fix: 3.1.6+
Fix from $1,950 2026-07-28
Dompdf HIGH 7.5
CVE-2026-55555

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack through the manipulation of the …

Fix: 3.16+
Fix from $1,950 2026-07-28
Dompdf CRITICAL 9.8
CVE-2021-3902

An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and dese…

Fix: 2.0.0+
Fix from $2,300 2024-11-15
Dompdf CRITICAL 9.8
CVE-2021-3838

DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the file_get_conte…

Fix: 2.0.0+
Fix from $2,300 2024-11-15
Dompdf HIGH 7.5
CVE-2023-50262

Dompdf is an HTML to PDF converter for PHP. When parsing SVG images Dompdf performs an initial validation to ensure that paths within the SVG are all…

Fix: after 2.0.3
Fix from $1,950 2023-12-13
Dompdf CRITICAL 9.8
CVE-2023-24813

Dompdf is an HTML to PDF converter written in php. Due to the difference in the attribute parser of Dompdf and php-svg-lib, an attacker can still cal…

Patch available
Fix from $2,300 2023-02-07
Dompdf CRITICAL 9.8
CVE-2023-23924

Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image>` tags with uppercase letter…

Patch available
Fix from $2,300 2023-02-01
Dompdf HIGH 7.5
CVE-2022-41343

registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration,…

Fix: 2.0.1+
Fix from $1,950 2022-09-25
Dompdf MEDIUM 5.3
CVE-2022-2400

External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.

Fix: 2.0.0+
Fix from $1,600 2022-07-18
Dompdf MEDIUM 5.3
CVE-2022-0085

Server-Side Request Forgery (SSRF) in GitHub repository dompdf/dompdf prior to 2.0.0.

Fix: 2.0.0+
Fix from $1,600 2022-06-28
Dompdf CRITICAL 9.8
CVE-2022-28368EPSS 82%

Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTM…

Fix: 1.2.1+
Fix from $2,300 2022-04-03
Dompdf HIGH 8.8
CVE-2014-5013

DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.

Fix: 0.6.2+
Fix from $1,950 2020-01-10
Dompdf MEDIUM 6.5
CVE-2014-5011

DOMPDF before 0.6.2 allows Information Disclosure.

Fix: 0.6.2+
Fix from $1,600 2020-01-10
Dompdf MEDIUM 6.5
CVE-2014-5012

DOMPDF before 0.6.2 allows denial of service.

Fix: 0.6.2+
Fix from $1,600 2020-01-10