Html2pdf Project maintains a document-conversion library that transforms HTML content into PDF format, a capability embedded in web applications and server-side workflows where it processes external or user-supplied input. The vulnerability profile centers on deserialization of untrusted data, cross-site scripting, and server-side request forgery issues that reflect the parsing and templating demands of HTML-to-PDF conversion. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Html2pdf Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45394HIGH An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious <link> tag in the converted HTML do | Jan 18, 2022 | 8.8 | 27 | NO | NO |
CVE-2023-39062MEDIUM Cross Site Scripting vulnerability in Spipu HTML2PDF before v.5.2.8 allows a remote attacker to execute arbitrary code via a crafted script to the forms.php. | Aug 28, 2023 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Html2pdf Project.
Media articles that mention a CVE ID that affects a product developed by Html2pdf Project — matched by CVE ID, not by vendor name.