Known Vulnerabilities for Dompdf by Dompdf Project
Listed below are 10 of the newest known vulnerabilities associated with "Dompdf" by "Dompdf Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-59943 json | Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content ... | Not Provided | 2026-07-28 | 2026-07-29 |
| CVE-2026-59942 json | Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via re... | Not Provided | 2026-07-28 | 2026-07-29 |
| CVE-2026-59941 json | Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG bas... | Not Provided | 2026-07-28 | 2026-07-29 |
| CVE-2026-56722 json | Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass t... | Not Provided | 2026-07-28 | 2026-07-29 |
| CVE-2026-55555 json | Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack through ... | Not Provided | 2026-07-28 | 2026-07-28 |
| CVE-2026-55554 json | Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot bound... | Not Provided | 2026-07-28 | 2026-07-29 |
| CVE-2023-24813 json | Dompdf is an HTML to PDF converter written in php. Due to the difference in the attribute parser of Dompdf and php-svg-lib, a... | 9.8 - CRITICAL | 2023-02-07 | 2023-02-16 |
| CVE-2023-23924 json | Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing ` |
9.8 - CRITICAL | 2023-02-01 | 2023-11-07 |
| CVE-2022-41343 json | registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not... | 7.5 - HIGH | 2022-09-25 | 2022-11-21 |
| CVE-2022-28368 json | Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) ... | 9.8 - CRITICAL | 2022-04-03 | 2023-08-08 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dompdf Project | Dompdf | 0.8.3 | |||
| Application | Dompdf Project | Dompdf | 0.8.2 | |||
| Application | Dompdf Project | Dompdf | 0.8.1 | |||
| Application | Dompdf Project | Dompdf | 0.8.0 | |||
| Application | Dompdf Project | Dompdf | 0.7.0 | |||
| Application | Dompdf Project | Dompdf | 0.6.2 | |||
| Application | Dompdf Project | Dompdf | 0.6.1 | |||
| Application | Dompdf Project | Dompdf | 0.6.0 | |||
| Application | Dompdf Project | Dompdf | 0.5.2 |