dompdf project records
18 published records for vendor dompdf project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 5.6%
- Pre-auth RCE
- 4
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation3
- CWE-400 Uncontrolled Resource Consumption2
- CWE-203 Observable Discrepancy1
- CWE-209 Generation of Error Message Containing Sensitive Information1
- CWE-436 Interpretation Conflict1
- CWE-502 Deserialization of Untrusted Data1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2022-28368Weaponized | Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (withdompdf project · dompdf · CWE-79 | Critical9.8 | — | 82.4% | Apr 2, 2022 |
40Plan | CVE-2023-23924Proof of concept | URI validation failure on SVG parsing in Dompdfdompdf project · dompdf · CWE-551 | Critical9.8 | — | 3.6% | Jan 31, 2023 |
40Plan | CVE-2023-24813No exploit | URI validation failure on SVG parsing. Bypass of CVE-2023-23924dompdf project · dompdf · CWE-436 | Critical9.8 | — | 2.5% | Feb 7, 2023 |
39Monitor | CVE-2021-3838No exploit | PHAR Deserialization in dompdf/dompdfdompdf project · dompdf · CWE-502 | Critical9.8 | — | 1.4% | Nov 15, 2024 |
39Monitor | CVE-2021-3902No exploit | Improper Restriction of XML External Entity Reference in dompdf/dompdfdompdf project · dompdf · CWE-611 | Critical9.8 | — | 1.0% | Nov 15, 2024 |
36Monitor | CVE-2014-5013No exploit | DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.dompdf project · dompdf | High8.8 | — | 4.5% | Jan 10, 2020 |
32Monitor | CVE-2022-41343Proof of concept | registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font regidompdf project · dompdf · CWE-552 | High7.5 | — | 6.0% | Sep 25, 2022 |
30Monitor | CVE-2023-50262No exploit | Dompdf possible DoS caused by infinite recursion when parsing SVG imagesdompdf project · dompdf · CWE-20 | High7.5 | — | 1.5% | Dec 13, 2023 |
26Monitor | CVE-2014-5011No exploit | DOMPDF before 0.6.2 allows Information Disclosure.dompdf project · dompdf · CWE-200 | Medium6.5 | — | 1.5% | Jan 10, 2020 |
26Monitor | CVE-2014-5012No exploit | DOMPDF before 0.6.2 allows denial of service.dompdf project · dompdf | Medium6.5 | — | 1.2% | Jan 10, 2020 |
25Monitor | CVE-2026-59942No exploit | Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmapsdompdf project · dompdf · CWE-400 | Medium6.3 | — | 0.9% | Jul 28, 2026 |
25Monitor | CVE-2026-59941Proof of concept | Dompdf: Uncontrolled resource consumption based on declared BMP dimensionsdompdf project · dompdf · CWE-400 | Medium6.3 | — | 0.6% | Jul 28, 2026 |
25Monitor | CVE-2026-56722No exploit | Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URIdompdf project · dompdf · CWE-20 | Medium6.3 | — | 0.4% | Jul 28, 2026 |
25Monitor | CVE-2026-59943No exploit | Dompdf: Embedded SVG images can leak existence of files and directories within the filesystemdompdf project · dompdf · CWE-209 | Medium6.3 | — | 0.4% | Jul 28, 2026 |
21Monitor | CVE-2022-2400No exploit | External Control of File Name or Path in dompdf/dompdfdompdf project · dompdf · CWE-73 | Medium5.3 | — | 1.2% | Jul 18, 2022 |
21Monitor | CVE-2022-0085No exploit | Server-Side Request Forgery (SSRF) in dompdf/dompdfdompdf project · dompdf · CWE-918 | Medium5.3 | — | 1.0% | Jun 28, 2022 |
9Monitor | CVE-2026-55555No exploit | Dompdf: File existence oracle via font-face stylesheet declarationdompdf project · dompdf · CWE-203 | Low2.3 | — | 0.5% | Jul 28, 2026 |
9Monitor | CVE-2026-55554No exploit | Dompdf: Chroot Validation Bypassdompdf project · dompdf · CWE-20 | Low2.3 | — | 0.5% | Jul 28, 2026 |
- CVE-2022-2836864This week
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (with
CriticalCVSS 9.8WeaponizedEPSS 82%dompdf project · dompdfApr 2, 2022
- CVE-2023-2392440Plan
URI validation failure on SVG parsing in Dompdf
CriticalCVSS 9.8Proof of conceptEPSS 4%dompdf project · dompdfJan 31, 2023
- CVE-2023-2481340Plan
URI validation failure on SVG parsing. Bypass of CVE-2023-23924
CriticalCVSS 9.8No exploitEPSS 2%dompdf project · dompdfFeb 7, 2023
- CVE-2021-383839Monitor
PHAR Deserialization in dompdf/dompdf
CriticalCVSS 9.8No exploitEPSS 1%dompdf project · dompdfNov 15, 2024
- CVE-2021-390239Monitor
Improper Restriction of XML External Entity Reference in dompdf/dompdf
CriticalCVSS 9.8No exploitEPSS 1%dompdf project · dompdfNov 15, 2024
- CVE-2014-501336Monitor
DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.
HighCVSS 8.8No exploitEPSS 4%dompdf project · dompdfJan 10, 2020
- CVE-2022-4134332Monitor
registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font regi
HighCVSS 7.5Proof of conceptEPSS 6%dompdf project · dompdfSep 25, 2022
- CVE-2023-5026230Monitor
Dompdf possible DoS caused by infinite recursion when parsing SVG images
HighCVSS 7.5No exploitEPSS 1%dompdf project · dompdfDec 13, 2023
- CVE-2014-501126Monitor
DOMPDF before 0.6.2 allows Information Disclosure.
MediumCVSS 6.5No exploitEPSS 1%dompdf project · dompdfJan 10, 2020
- CVE-2014-501226Monitor
DOMPDF before 0.6.2 allows denial of service.
MediumCVSS 6.5No exploitEPSS 1%dompdf project · dompdfJan 10, 2020
- CVE-2026-5994225Monitor
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
MediumCVSS 6.3No exploitEPSS 1%dompdf project · dompdfJul 28, 2026
- CVE-2026-5994125Monitor
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
MediumCVSS 6.3Proof of conceptEPSS 1%dompdf project · dompdfJul 28, 2026
- CVE-2026-5672225Monitor
Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
MediumCVSS 6.3No exploitEPSS 0%dompdf project · dompdfJul 28, 2026
- CVE-2026-5994325Monitor
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem
MediumCVSS 6.3No exploitEPSS 0%dompdf project · dompdfJul 28, 2026
- CVE-2022-240021Monitor
External Control of File Name or Path in dompdf/dompdf
MediumCVSS 5.3No exploitEPSS 1%dompdf project · dompdfJul 18, 2022
- CVE-2022-008521Monitor
Server-Side Request Forgery (SSRF) in dompdf/dompdf
MediumCVSS 5.3No exploitEPSS 1%dompdf project · dompdfJun 28, 2022
- CVE-2026-555559Monitor
Dompdf: File existence oracle via font-face stylesheet declaration
LowCVSS 2.3No exploitEPSS 1%dompdf project · dompdfJul 28, 2026
- CVE-2026-555549Monitor
Dompdf: Chroot Validation Bypass
LowCVSS 2.3No exploitEPSS 0%dompdf project · dompdfJul 28, 2026