Skip to content
Noroxi

dompdf project records

18 published records for vendor dompdf project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 5.6%
Pre-auth RCE
4
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

18 records
  • CVE-2022-28368
    64This week

    Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (with

    CriticalCVSS 9.8WeaponizedEPSS 82%

    dompdf project · dompdfApr 2, 2022

  • URI validation failure on SVG parsing in Dompdf

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    dompdf project · dompdfJan 31, 2023

  • URI validation failure on SVG parsing. Bypass of CVE-2023-23924

    CriticalCVSS 9.8No exploitEPSS 2%

    dompdf project · dompdfFeb 7, 2023

  • CVE-2021-3838
    39Monitor

    PHAR Deserialization in dompdf/dompdf

    CriticalCVSS 9.8No exploitEPSS 1%

    dompdf project · dompdfNov 15, 2024

  • CVE-2021-3902
    39Monitor

    Improper Restriction of XML External Entity Reference in dompdf/dompdf

    CriticalCVSS 9.8No exploitEPSS 1%

    dompdf project · dompdfNov 15, 2024

  • CVE-2014-5013
    36Monitor

    DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.

    HighCVSS 8.8No exploitEPSS 4%

    dompdf project · dompdfJan 10, 2020

  • registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font regi

    HighCVSS 7.5Proof of conceptEPSS 6%

    dompdf project · dompdfSep 25, 2022

  • Dompdf possible DoS caused by infinite recursion when parsing SVG images

    HighCVSS 7.5No exploitEPSS 1%

    dompdf project · dompdfDec 13, 2023

  • CVE-2014-5011
    26Monitor

    DOMPDF before 0.6.2 allows Information Disclosure.

    MediumCVSS 6.5No exploitEPSS 1%

    dompdf project · dompdfJan 10, 2020

  • CVE-2014-5012
    26Monitor

    DOMPDF before 0.6.2 allows denial of service.

    MediumCVSS 6.5No exploitEPSS 1%

    dompdf project · dompdfJan 10, 2020

  • Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps

    MediumCVSS 6.3No exploitEPSS 1%

    dompdf project · dompdfJul 28, 2026

  • Dompdf: Uncontrolled resource consumption based on declared BMP dimensions

    MediumCVSS 6.3Proof of conceptEPSS 1%

    dompdf project · dompdfJul 28, 2026

  • Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI

    MediumCVSS 6.3No exploitEPSS 0%

    dompdf project · dompdfJul 28, 2026

  • Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem

    MediumCVSS 6.3No exploitEPSS 0%

    dompdf project · dompdfJul 28, 2026

  • CVE-2022-2400
    21Monitor

    External Control of File Name or Path in dompdf/dompdf

    MediumCVSS 5.3No exploitEPSS 1%

    dompdf project · dompdfJul 18, 2022

  • CVE-2022-0085
    21Monitor

    Server-Side Request Forgery (SSRF) in dompdf/dompdf

    MediumCVSS 5.3No exploitEPSS 1%

    dompdf project · dompdfJun 28, 2022

  • Dompdf: File existence oracle via font-face stylesheet declaration

    LowCVSS 2.3No exploitEPSS 1%

    dompdf project · dompdfJul 28, 2026

  • Dompdf: Chroot Validation Bypass

    LowCVSS 2.3No exploitEPSS 0%

    dompdf project · dompdfJul 28, 2026