VendorsTcpdf Projecttcpdfany version
Vulnerabilities

Tcpdf Project Tcpdf any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2024-56521
An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CURLOPT_SSL_VERIFYHOST and CURLOPT_SSL_VERIFYPEER are set unsafely.
Published 2024-12-27 · Analyzed
9.8EPSS 0.008
CVE-2017-6100
tcpdf before 6.2.0 uploads files from the server generating PDF-files to an external FTP.
Published 2017-02-23 · Modified
7.5EPSS 0.015
CVE-2024-22640
TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.
Published 2024-04-19 · Modified
7.5EPSS 0.013
CVE-2024-22641
TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.
Published 2024-05-28 · Modified
7.5EPSS 0.011
CVE-2024-56527
An issue was discovered in TCPDF before 6.8.0. The Error function lacks an htmlspecialchars call for the error message.
Published 2024-12-27 · Modified
7.5EPSS 0.008
CVE-2024-56519
An issue was discovered in TCPDF before 6.8.0. setSVGStyles does not sanitize the SVG font-family attribute.
Published 2024-12-27 · Modified
7.5EPSS 0.006
CVE-2024-56522
An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a constant-time function to compare TCPDF tag hashes.
Published 2024-12-27 · Modified
7.5EPSS 0.006
CVE-2024-32489
TCPDF before 6.7.4 mishandles calls that use HTML syntax.
Published 2024-04-15 · Modified
6.1EPSS 0.006