Known Vulnerabilities for products from Dompdf Project
Listed below are 15 of the newest known vulnerabilities associated with the vendor "Dompdf Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-59943 json | Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content ... | Not Provided | 2026-07-28 | 2026-08-04 |
| CVE-2026-59942 json | Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via re... | Not Provided | 2026-07-28 | 2026-08-04 |
| CVE-2026-59941 json | Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG bas... | Not Provided | 2026-07-28 | 2026-08-04 |
| CVE-2026-56722 json | Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass t... | Not Provided | 2026-07-28 | 2026-08-04 |
| CVE-2026-55555 json | Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack through ... | Not Provided | 2026-07-28 | 2026-08-05 |
| CVE-2026-55554 json | Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot bound... | Not Provided | 2026-07-28 | 2026-08-05 |
| CVE-2023-24813 json | Dompdf is an HTML to PDF converter written in php. Due to the difference in the attribute parser of Dompdf and php-svg-lib, a... | 9.8 - CRITICAL | 2023-02-07 | 2023-02-16 |
| CVE-2023-23924 json | Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing ` |
9.8 - CRITICAL | 2023-02-01 | 2023-11-07 |
| CVE-2022-41343 json | registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not... | 7.5 - HIGH | 2022-09-25 | 2022-11-21 |
| CVE-2022-28368 json | Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) ... | 9.8 - CRITICAL | 2022-04-03 | 2023-08-08 |
| CVE-2022-2400 json | External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0. | 5.3 - MEDIUM | 2022-07-18 | 2023-07-13 |
| CVE-2022-0085 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.3 - MEDIUM | 2022-06-28 | 2022-07-07 |
| CVE-2014-5013 json | DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383. | 8.8 - HIGH | 2020-01-10 | 2020-01-13 |
| CVE-2014-5012 json | DOMPDF before 0.6.2 allows denial of service. | 6.5 - MEDIUM | 2020-01-10 | 2020-01-13 |
| CVE-2014-5011 json | DOMPDF before 0.6.2 allows Information Disclosure. | 6.5 - MEDIUM | 2020-01-10 | 2020-01-13 |
Known software with vulnerabilities from Dompdf Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Dompdf Project | Dompdf | 0.5.2 |