CVE-2022-50897: Mpdf Project Mpdf
Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.
mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulating annotation file parameters. Attackers can generate URL-encoded or base64 payloads to include local files through crafted annotation content with file path specifications.
Affected products
- Mpdf Project Mpdf: version 7.0.0 only
Published 2026-01-13. Last modified 2026-06-17.