Mpdf
Mpdf Project · 4 CVEs
CVE-2022-50897
HIGH
mPDF 7.0 - Local File Inclusion
Jan 13, 2026
CVE-2024-26476
LOW
An issue in open-emr before v.7.0.2 allows a remote attacker to escalate privileges via a crafted script to the formid…
Feb 28, 2024
CVE-2019-1000005
HIGH
mPDF version 7.1.7 and earlier contains a CWE-502: Deserialization of Untrusted Data vulnerability in getImage() method…
Feb 4, 2019
CVE-2018-19047
CRITICAL
mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<i…
Nov 7, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2022-50897 | mPDF 7.0 - Local File Inclusion | HIGH | 0.55% | Jan 13, 2026 |
| CVE-2024-26476 | An issue in open-emr before v.7.0.2 allows a remote attacker to escalate privileges via a crafted script to the formid parameter in the ereq_form.php component. | LOW | 0.41% | Feb 28, 2024 |
| CVE-2019-1000005 | mPDF version 7.1.7 and earlier contains a CWE-502: Deserialization of Untrusted Data vulnerability in getImage() method of Image/ImageProcessor class that can… | HIGH | 2.10% | Feb 4, 2019 |
| CVE-2018-19047 | mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<img src="http://192.168' substring that t… | CRITICAL | 2.08% | Nov 7, 2018 |
Showing 1 to 4 of 4 CVEs