Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-17057

52
FAUCET Score

CVE-2018-17057 is a critical deserialization vulnerability in TCPDF versions prior to 6.2.22, specifically affecting products like LimeSurvey that integrate TCPDF. Attackers can exploit this flaw via the phar:// wrapper to trigger deserialization of arbitrary data, potentially leading to remote code execution. With a CVSS score of 9.8 (CRITICAL) and no user interaction required, this vulnerability presents a significant risk for complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-46634) confirms active exploitation capabilities for LimeSurvey, despite limited community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 6.2.22CPE matchmatch criteria
cpe:2.3:a:tecnick:tcpdf:*:*:*:*:*:*:*:*
< 3.16.0CPE matchmatch criteria
cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

9.8CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
26.17%
Probability of exploitation in next 30 days
EPSS Percentile
97.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-46634 · Apr 2, 2019
This CVE's current EPSS score of 0.2617 is in the 95th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

composerpatch availablevia ghsa
Product: tecnickcom/tcpdfFixed in: 6.2.22
composerpatch availablevia ghsa
Product: fooman/tcpdfFixed in: 6.2.22
composerpatch availablevia ghsa
Product: la-haute-societe/tcpdfFixed in: 6.2.22
composerpatch availablevia ghsa
Product: spoonity/tcpdfFixed in: 6.2.22
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-5hw4-m7f3-hhx8critical

TCPDF vulnerable to attackers triggering deserialization of arbitrary data

Oct 6, 2022

References

packetstormsecurity.com / files/152200/TCPDF-6.2.19-Deserialization-Remote-Code-Execution.html
Third Party AdvisoryVDB Entry
packetstormsecurity.com / files/152360/LimeSurvey-Deserialization-Remote-Code-Execution.html
ExploitThird Party AdvisoryVDB Entry
contao.org / en/news/security-vulnerability-cve-2018-17057.html
Third Party Advisory
seclists.org / fulldisclosure/2019/Mar/36
Mailing ListThird Party Advisory
github.com / LimeSurvey/LimeSurvey/commit/1cdd78d27697b3150bb44aaa7af1a81062a591a5
PatchThird Party Advisory
github.com / tecnickcom/TCPDF/commit/1861e33fe05f653b67d070f7c106463e7a5c26ed
PatchThird Party Advisory
exploit-db.com / exploits/46634
Third Party AdvisoryVDB Entry