Known Vulnerabilities for Dompdf by Dompdf Project
Listed below are 9 of the newest known vulnerabilities associated with "Dompdf" by "Dompdf Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-8193 json | A weakness has been identified in Akaunting 3.1.21. This issue affects some unknown processing of the file config/dompdf.php ... | Not Provided | 2026-05-09 | 2026-05-09 |
| CVE-2023-24813 json | Dompdf is an HTML to PDF converter written in php. Due to the difference in the attribute parser of Dompdf and php-svg-lib, a... | 9.8 - CRITICAL | 2023-02-07 | 2023-02-16 |
| CVE-2023-23924 json | Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing ` |
9.8 - CRITICAL | 2023-02-01 | 2023-11-07 |
| CVE-2022-41343 json | registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not... | 7.5 - HIGH | 2022-09-25 | 2022-11-21 |
| CVE-2022-28368 json | Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) ... | 9.8 - CRITICAL | 2022-04-03 | 2023-08-08 |
| CVE-2022-2400 json | External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0. | 5.3 - MEDIUM | 2022-07-18 | 2023-07-13 |
| CVE-2022-0085 json | Server-Side Request Forgery (SSRF) in GitHub repository dompdf/dompdf prior to 2.0.0. | 5.3 - MEDIUM | 2022-06-28 | 2022-07-07 |
| CVE-2014-5013 json | DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383. | 8.8 - HIGH | 2020-01-10 | 2020-01-13 |
| CVE-2014-5012 json | DOMPDF before 0.6.2 allows denial of service. | 6.5 - MEDIUM | 2020-01-10 | 2020-01-13 |
| CVE-2014-5011 json | DOMPDF before 0.6.2 allows Information Disclosure. | 6.5 - MEDIUM | 2020-01-10 | 2020-01-13 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dompdf Project | Dompdf | 0.8.3 | |||
| Application | Dompdf Project | Dompdf | 0.8.2 | |||
| Application | Dompdf Project | Dompdf | 0.8.1 | |||
| Application | Dompdf Project | Dompdf | 0.8.0 | |||
| Application | Dompdf Project | Dompdf | 0.7.0 | |||
| Application | Dompdf Project | Dompdf | 0.6.2 | |||
| Application | Dompdf Project | Dompdf | 0.6.1 | |||
| Application | Dompdf Project | Dompdf | 0.6.0 | |||
| Application | Dompdf Project | Dompdf | 0.5.2 |