Composer package intelligence

dompdf/dompdf Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Composer package dompdf/dompdf, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
1
Known exploited vulnerability affecting dompdf/dompdf
In CISA KEV
0
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
1
dompdf/dompdf KEV with sensor-observed exploitation activity

Review dompdf/dompdf exploitation against the versions you run

One of the one exploited dompdf/dompdf vulnerabilities tracked here are not in CISA KEV.

0%
Covered by CISA
100%
Beyond CISA

Attested dompdf/dompdf vulnerabilities

1 known exploited vulnerability affecting this package.

Vulnerability CISA KEV Added
CVE-2014-2383

dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read...

Beyond CISA 25 Jul 2026

Recurring weakness patterns

Exposure of Sensitive Information to an Unauthorized Actor account for mapped occurrences across this dompdf/dompdf KEV portfolio.

Browse all KEVs →