Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2024-1647

Disclosure Date: February 20, 2024 (last updated February 13, 2025)
Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user.
0
Attacker Value
Unknown

CVE-2023-39062

Disclosure Date: August 28, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability in Spipu HTML2PDF before v.5.2.8 allows a remote attacker to execute arbitrary code via a crafted script to the forms.php.
Attacker Value
Unknown

CVE-2021-45394

Disclosure Date: January 18, 2022 (last updated February 23, 2025)
An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious <link> tag in the converted HTML document.