CVE Tools

Dompdf

1 CVEs tracked since 2014. Since Apr 2014, none of them reached CISA KEV.

Dompdf CVEs per month

Apr 2014 to Apr 2014. Point at a month, or focus the strip and use the arrow keys.
Dompdf CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2014-0410

Products

The products that kept showing up in Dompdf's monthly top three, with their CVEs summed over those months.

  1. Dompdf11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Dompdf.

  1. CVE-2026-59941Dompdf: Uncontrolled resource consumption based on declared BMP dimensions7.5
  2. CVE-2026-59942Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps7.5
  3. CVE-2026-59943Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem5.3
  4. CVE-2026-56722Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI5.3
  5. CVE-2026-55554Dompdf: Chroot Validation Bypass7.5
  6. CVE-2026-55555Dompdf: File existence oracle via font-face stylesheet declaration7.5
  7. CVE-2021-3902Improper Restriction of XML External Entity Reference in dompdf/dompdf9.8
  8. CVE-2021-3838PHAR Deserialization in dompdf/dompdf9.8
  9. CVE-2024-25117php-svg-lib lacks path validation on font through SVG inline styles 6.8
  10. CVE-2023-50262Dompdf possible DoS caused by infinite recursion when parsing SVG images5.3
  11. CVE-2023-50252php-svg-lib unsafe attributes merge when parsing `use` tag8.3
  12. CVE-2023-50251php-svg-lib possible DoS caused by infinite recursion when parsing SVG document5.3
  13. CVE-2023-24813URI validation failure on SVG parsing. Bypass of CVE-2023-2392410.0
  14. CVE-2023-23924URI validation failure on SVG parsing in Dompdf10.0
  15. CVE-2022-2400External Control of File Name or Path in dompdf/dompdf5.3

The record

Peak rank
#135 in Apr 2014
Busiest month shown
Apr 2014, 1 CVEs
Months with a KEV entry
0 since Apr 2014
Monthly snapshots
1 since 2014
Dompdf's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store