← Back

Tcpdf Project

tcpdf_project

9 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Tcpdf
tcpdf

CVEs (9)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tcpdf Project
1Tcpdf
Nov 3, 2025
Dec 27, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in TCPDF before 6.8.0. The Error function lacks an htmlspecialchars call for the error message.
1Tcpdf Project
1Tcpdf
Nov 3, 2025
Dec 27, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a constant-time function to compare TCPDF tag hashes.
1Tcpdf Project
1Tcpdf
Apr 21, 2025
Dec 27, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CURLOPT_SSL_VERIFYHOST and CURLOPT_SSL_VERIFYPEER are set unsafely.
1Tcpdf Project
1Tcpdf
Nov 3, 2025
Dec 27, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in TCPDF before 6.8.0. setSVGStyles does not sanitize the SVG font-family attribute.
1Tcpdf Project
1Tcpdf
Nov 3, 2025
Nov 26, 2024
N/A· v4
6.2 MEDIUM· v3
N/A· v2
Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read arbitrary files from the server's file system through <img> src tag, potentially exposing sensitive i...Show more
Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read arbitrary files from the server's file system through <img> src tag, potentially exposing sensitive information.Show less
1Tcpdf Project
1Tcpdf
Nov 3, 2025
May 28, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.
2Fedoraproject
Tcpdf Project
2Fedora
Tcpdf
Nov 4, 2025
Apr 19, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.
1Tcpdf Project
1Tcpdf
Nov 3, 2025
Apr 15, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
TCPDF before 6.7.4 mishandles calls that use HTML syntax.
1Tcpdf Project
1Tcpdf
May 13, 2026
Feb 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
tcpdf before 6.2.0 uploads files from the server generating PDF-files to an external FTP.