Mpdf

Vendor:

First CVE: Nov 7, 2018 · Active for 7 years

3
Total CVEs
More Total CVEs than 64% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
8.1
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Mpdf over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 7, 2018
7 years ago
Most Recent CVE
Jan 13, 2026
192 days ago

CVE Severity & Scoring

Mpdf3 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local1 (33.3%)
Network2 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (66.7%)
Unknown0 (0.0%)
Required1 (33.3%)
Privileges Required
Low1 (33.3%)
High0 (0.0%)
None2 (66.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (3 CVEs).

3 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<img src="http://192.168' substring that triggers a call to get
Nov 7, 201810.032NONO
mPDF version 7.1.7 and earlier contains a CWE-502: Deserialization of Untrusted Data vulnerability in getImage() method of Image/ImageProcessor class that can result in Arbitry cod
Feb 4, 20198.826NONO
mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulating annotation file parameters. Attackers can generate URL-e
Jan 13, 20265.523NONO

Exploit Exposure

Signals from CVEs in this product scope (3 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (3 CVEs).

Media Mentions

Signals from CVEs in this product scope (3 CVEs).

Top CNAs Publishing CVEs For Mpdf

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.0.015.50.5%00