Wkhtmltopdf is an open-source HTML-to-PDF conversion utility widely embedded in web applications and document-generation pipelines, where its exposure to untrusted input creates recurring vulnerabilities. The observed weakness classes—path traversal, server-side request forgery, and related input-handling flaws—reflect the challenge of safely processing external HTML content and controlling file-system and network access within a conversion tool. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wkhtmltopdf over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-35583CRITICAL wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's sourc | Aug 22, 2022 | 9.8 | 46 | NO | YES |
CVE-2020-21365HIGH Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with | Aug 15, 2022 | 7.5 | 26 | NO | NO |
CVE-2024-13285CRITICAL Vulnerability in Drupal wkhtmltopdf.This issue affects wkhtmltopdf: *.*. | Jan 9, 2025 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wkhtmltopdf.
Media articles that mention a CVE ID that affects a product developed by Wkhtmltopdf — matched by CVE ID, not by vendor name.