Mpdf is a PHP-based PDF generation library widely embedded in web applications and content-management systems, presenting a supply-chain exposure where a single flaw can affect many downstream products. The recurring vulnerability patterns center on deserialization of untrusted data, PHP remote file inclusion, and server-side request forgery—reflecting the library's role in processing and rendering user-supplied content into PDF output. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mpdf Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19047CRITICAL mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<img src="http://192.168' substring that triggers a call to get | Nov 7, 2018 | 10.0 | 32 | NO | NO |
CVE-2019-1000005HIGH mPDF version 7.1.7 and earlier contains a CWE-502: Deserialization of Untrusted Data vulnerability in getImage() method of Image/ImageProcessor class that can result in Arbitry cod | Feb 4, 2019 | 8.8 | 26 | NO | NO |
CVE-2022-50897MEDIUM mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulating annotation file parameters. Attackers can generate URL-e | Jan 13, 2026 | 5.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mpdf Project.
Media articles that mention a CVE ID that affects a product developed by Mpdf Project — matched by CVE ID, not by vendor name.