Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

dompdf — Vulnerabilities & Security Advisories 16

Browse all 16 CVE security advisories affecting dompdf. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Dompdf is a PHP library for converting HTML to PDF, widely used for generating documents dynamically. Historically, it has been vulnerable to multiple remote code execution (RCE) flaws due to unsafe processing of untrusted input, allowing attackers to execute arbitrary code. Cross-site scripting (XSS) vulnerabilities have also been common through improper output sanitization. The library has faced privilege escalation issues in certain configurations. With 10 CVEs recorded, dompdf's security posture has been periodically compromised, with some vulnerabilities enabling complete system compromise when deployed with elevated privileges or in shared hosting environments. Its parsing of complex HTML and CSS remains a persistent attack surface.

CVE ID Title CVSS Severity Published
CVE-2026-59941 Dompdf: Uncontrolled resource consumption based on declared BMP dimensions — dompdf CWE-400 6.3 Medium 2026-07-28
CVE-2026-59942 Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps — dompdf CWE-400 6.3 Medium 2026-07-28
CVE-2026-59943 Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem — dompdf CWE-209 6.3 Medium 2026-07-28
CVE-2026-56722 Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI — dompdf CWE-20 6.3 Medium 2026-07-28
CVE-2026-55554 Dompdf: Chroot Validation Bypass — dompdf CWE-20 2.3 Low 2026-07-28
CVE-2026-55555 Dompdf: File existence oracle via font-face stylesheet declaration — dompdf CWE-203 2.3 Low 2026-07-28
CVE-2021-3902 Improper Restriction of XML External Entity Reference in dompdf/dompdf — dompdf/dompdf CWE-611 8.1AI High AI 2024-11-15
CVE-2021-3838 PHAR Deserialization in dompdf/dompdf — dompdf/dompdf CWE-502 8.8 - 2024-11-15
CVE-2024-25117 php-svg-lib lacks path validation on font through SVG inline styles — php-svg-lib CWE-73 6.8 Medium 2024-02-21
CVE-2023-50262 Dompdf possible DoS caused by infinite recursion when parsing SVG images — dompdf CWE-20 5.3 Medium 2023-12-13
CVE-2023-50252 php-svg-lib unsafe attributes merge when parsing `use` tag — php-svg-lib CWE-15 8.3 High 2023-12-12
CVE-2023-50251 php-svg-lib possible DoS caused by infinite recursion when parsing SVG document — php-svg-lib CWE-674 5.3 Medium 2023-12-12
CVE-2023-24813 URI validation failure on SVG parsing. Bypass of CVE-2023-23924 — dompdf CWE-436 10.0 Critical 2023-02-07
CVE-2023-23924 URI validation failure on SVG parsing in Dompdf — dompdf CWE-551 10.0 Critical 2023-01-31
CVE-2022-2400 External Control of File Name or Path in dompdf/dompdf — dompdf/dompdf CWE-73 8.2 - 2022-07-18
CVE-2022-0085 Server-Side Request Forgery (SSRF) in dompdf/dompdf — dompdf/dompdf CWE-918 7.5 - 2022-06-28

This page lists every published CVE security advisory associated with dompdf. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.