VendorsDompdf Projectdompdfall versions
Vulnerabilities

Dompdf Project Dompdf

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2023-23924
URI validation failure on SVG parsing in Dompdf
Published 2023-01-31 · Modified
10.0EPSS 0.036
CVE-2023-24813
URI validation failure on SVG parsing. Bypass of CVE-2023-23924
Published 2023-02-07 · Modified
10.0EPSS 0.025
CVE-2022-28368
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).
Published 2022-04-03 · Modified
9.81 PoCEPSS 0.824
CVE-2021-3838
PHAR Deserialization in dompdf/dompdf
Published 2024-11-15 · Analyzed
9.8EPSS 0.014
CVE-2021-3902
Improper Restriction of XML External Entity Reference in dompdf/dompdf
Published 2024-11-15 · Analyzed
9.8EPSS 0.010
CVE-2014-5013
DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.
Published 2020-01-10 · Modified
8.8EPSS 0.045
CVE-2022-41343
registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule.
Published 2022-09-25 · Modified
7.5EPSS 0.060
CVE-2023-50262
Dompdf possible DoS caused by infinite recursion when parsing SVG images
Published 2023-12-13 · Modified
7.5EPSS 0.015
CVE-2026-59942
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
Published 2026-07-28 · Analyzed
7.5EPSS 0.009
CVE-2026-59941
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
Published 2026-07-28 · Analyzed
7.5EPSS 0.006
CVE-2026-55555
Dompdf: File existence oracle via font-face stylesheet declaration
Published 2026-07-28 · Analyzed
7.5EPSS 0.005
CVE-2026-55554
Dompdf: Chroot Validation Bypass
Published 2026-07-28 · Analyzed
7.5EPSS 0.005
CVE-2014-5011
DOMPDF before 0.6.2 allows Information Disclosure.
Published 2020-01-10 · Modified
6.5EPSS 0.015
CVE-2014-5012
DOMPDF before 0.6.2 allows denial of service.
Published 2020-01-10 · Modified
6.5EPSS 0.012
CVE-2026-56722
Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
Published 2026-07-28 · Analyzed
6.3EPSS 0.004
CVE-2026-59943
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem
Published 2026-07-28 · Analyzed
6.3EPSS 0.004
CVE-2022-2400
External Control of File Name or Path in dompdf/dompdf
Published 2022-07-18 · Modified
5.3EPSS 0.012
CVE-2022-0085
Server-Side Request Forgery (SSRF) in dompdf/dompdf
Published 2022-06-28 · Modified
5.3EPSS 0.010